vl-ui-action-group@10.1.1
Malicious code in vl-ui-action-group (npm)
Analysis
vl-ui-action-group@10.1.1 is a dependency-confusion recon package. Both the preinstall and postinstall hooks execute curl to send host reconnaissance data to hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/ via GET query parameters. The exfiltrated data includes the package name, the current username ($(whoami)), hostname ($(hostname)), working directory ($PWD), and install timestamp ($(date +%s)). The package's index.js is an empty stub and the description is misleading — the package has no real functionality beyond these data-gathering lifecycle hooks.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:58 PM
- analyzed
- Jun 15, 2026, 09:00 PM
Related advisories
- viem-ethereum@2.47.9
- thepackagethatworks_@1.0.2
- system-driver@1.0.1
- sort-btree@2.1.4
- seed-to-private@1.0.1
- saps_secplayground_npm_ai@1.0.4
- redeem-onchain-sdk@1.0.1
- pino-pretty-logs@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.