LWA-2026-5437 confirmed malware

vl-ui-button@10.1.1

Malicious code in vl-ui-button (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package vl-ui-button@10.1.1 is a combosquat of the legitimate @vl-ui/button package that contains no real functionality. Both its preinstall and postinstall lifecycle hooks send an HTTP GET request to 178fx66q[.]instances[.]httpworkbench[.]com with the installer's username (`whoami`), hostname, current working directory, and a timestamp collected as query parameters. The output of the curl commands is discarded to /dev/null and errors are masked with `|| true` for stealth. The host is an HTTP Workbench instance acting as a webhook receiver for attacker collection. This is a dependency-confusion reconnaissance beacon designed to identify systems that install it.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:58 PM
analyzed
Jun 15, 2026, 09:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.