LWA-2026-3980 confirmed malware
mkt-ui-library@45.0.0
Malicious code in mkt-ui-library (npm)
T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShell
Analysis
mkt-ui-library declares a self-dependency via an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/mkt-ui-library) to serve a malicious tarball at install time while keeping the registry publish clean. The package is a ~533-byte stub with a benign index.js that logs a message and a README claiming it is a placeholder to prevent dependency confusion — but a real placeholder would not self-reference via an external-URL dependency. The external URL can serve any payload at install time without leaving traces in the registry tarball.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 06:07 PM
- analyzed
- Jun 10, 2026, 06:08 PM
Related advisories
- @solana-js/web3@1.91.3
- @coralxyz/anchor@0.30.2
- @rbx-ts/services@1.6.0
- wormgpt-cli@1.0.1
- dolyame-ui-swiper@35.7.7
- stellarfixer@1.0.0
- approval-guardian@1.0.8
- warp-drive-internal-tooling@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.