vl-ui-code-preview@10.1.1
Malicious code in vl-ui-code-preview (npm)
Analysis
Dependency-confusion package impersonating the Flemish government's @govflanders/vl-ui-code-preview library. The unscoped vl-ui-code-preview@10.1.1 ships a 55-byte placeholder index.js with no functional code. Both preinstall and postinstall hooks execute curl commands that exfiltrate system metadata (username via whoami, hostname, current working directory, and current timestamp) to the external endpoint hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/. The URL path /depconf/ and parameters (pkg, u, h, d, t) indicate targeted dependency-confusion reconnaissance measuring which environments are susceptible to the attack.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:13 PM
- analyzed
- Jun 15, 2026, 09:14 PM
Related advisories
- vl-ui-body@10.1.1
- vl-ui-breadcrumb@10.1.1
- vl-ui-checkbox@10.1.1
- vl-ui-alert@99.99.2
- vl-ui-accessibility@99.99.1
- unico-check@9.9.9
- unico-android@9.9.9
- field-plus@99.99.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.