vl-ui-button@10.1.1
Malicious code in vl-ui-button (npm)
Analysis
The package vl-ui-button@10.1.1 is a combosquat of the legitimate @vl-ui/button package that contains no real functionality. Both its preinstall and postinstall lifecycle hooks send an HTTP GET request to 178fx66q[.]instances[.]httpworkbench[.]com with the installer's username (`whoami`), hostname, current working directory, and a timestamp collected as query parameters. The output of the curl commands is discarded to /dev/null and errors are masked with `|| true` for stealth. The host is an HTTP Workbench instance acting as a webhook receiver for attacker collection. This is a dependency-confusion reconnaissance beacon designed to identify systems that install it.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:58 PM
- analyzed
- Jun 15, 2026, 09:00 PM
Related advisories
- vl-ui-breadcrumb@10.1.1
- vl-ui-alert@99.99.2
- vl-ui-accessibility@99.99.1
- @httpactions/encode-url@1.0.0
- vend-utilities@14.12.11
- vfat-tools@2.0.0
- typescript-util-core@7.1.5
- vault-strategies@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.