LWA-2026-5438 confirmed malware
vl-ui-checkbox@10.1.1
Malicious code in vl-ui-checkbox (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
Trojanized clone of the vl-ui-checkbox UI component. Both the preinstall and postinstall lifecycle hooks execute a curl command that beacons system reconnaissance data (username, hostname, current working directory, and timestamp) to hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/ via HTTP GET parameters. The package contains no functional code — index.js is a 55-byte comment-only placeholder. This is a dependency-confusion implant designed to probe the installation environment for follow-up targeting.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:58 PM
- analyzed
- Jun 15, 2026, 08:59 PM
Related advisories
- vl-ui-alert@99.99.2
- vl-ui-accessibility@99.99.1
- unico-check@9.9.9
- unico-android@9.9.9
- field-plus@99.99.1
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.