LWA-2026-5383 confirmed malware
ux-metrics-client-interaction-subscriber@45.0.0
Malicious code in ux-metrics-client-interaction-subscriber (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Package declares a dependency on itself resolved from the external URL hxxps://repo[.]securityctrl[.]com/ux-metrics-client-interaction-subscriber. During npm install, this causes the package manager to fetch code from an attacker-controlled remote host, which can serve arbitrary malicious content. The local tarball is a trivial placeholder with no real functionality — the actual payload is delivered at install time from the external URL.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:16 PM
- analyzed
- Jun 15, 2026, 02:17 PM
Related advisories
- bubblestr@1.1.4
- util-free-ports@3.1.2
- vitest-pro@7.0.4
- unicode-colors@4.1.4
- typescript-util-core@3.5.0
- twcompose-utils@0.7.6
- ts-webplug@3.0.5
- tsliverhome@1.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.