LWA-2026-5436 confirmed malware
vl-ui-breadcrumb@10.1.1
Malicious code in vl-ui-breadcrumb (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Installing this package triggers both preinstall and postinstall hooks that curl a remote server at 178fx66q[.]instances[.]httpworkbench[.]com with host recon data: the current username (whoami), hostname, working directory ($PWD), and install timestamp. The URL path /depconf/ and the package name (tailored to collide with a real UI component library namespace) indicate a targeted dependency-confusion attack. The package contains no functional code — index.js is an empty stub.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:58 PM
- analyzed
- Jun 15, 2026, 08:59 PM
Related advisories
- vl-ui-checkbox@10.1.1
- vl-ui-alert@99.99.2
- vl-ui-accessibility@99.99.1
- unico-check@9.9.9
- unico-android@9.9.9
- field-plus@99.99.1
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.