LWA-2026-5383 confirmed malware

ux-metrics-client-interaction-subscriber@45.0.0

Malicious code in ux-metrics-client-interaction-subscriber (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package declares a dependency on itself resolved from the external URL hxxps://repo[.]securityctrl[.]com/ux-metrics-client-interaction-subscriber. During npm install, this causes the package manager to fetch code from an attacker-controlled remote host, which can serve arbitrary malicious content. The local tarball is a trivial placeholder with no real functionality — the actual payload is delivered at install time from the external URL.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:16 PM
analyzed
Jun 15, 2026, 02:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.