LWA-2026-5436 confirmed malware

vl-ui-breadcrumb@10.1.1

Malicious code in vl-ui-breadcrumb (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Installing this package triggers both preinstall and postinstall hooks that curl a remote server at 178fx66q[.]instances[.]httpworkbench[.]com with host recon data: the current username (whoami), hostname, working directory ($PWD), and install timestamp. The URL path /depconf/ and the package name (tailored to collide with a real UI component library namespace) indicate a targeted dependency-confusion attack. The package contains no functional code — index.js is an empty stub.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:58 PM
analyzed
Jun 15, 2026, 08:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.