LWA-2026-5433 confirmed malware

vl-ui-action-group@10.1.1

Malicious code in vl-ui-action-group (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1567 · Exfiltration Over Web Service

Analysis

vl-ui-action-group@10.1.1 is a dependency-confusion recon package. Both the preinstall and postinstall hooks execute curl to send host reconnaissance data to hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/ via GET query parameters. The exfiltrated data includes the package name, the current username ($(whoami)), hostname ($(hostname)), working directory ($PWD), and install timestamp ($(date +%s)). The package's index.js is an empty stub and the description is misleading — the package has no real functionality beyond these data-gathering lifecycle hooks.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:58 PM
analyzed
Jun 15, 2026, 09:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.