LWA-2026-5440 confirmed malware

vl-ui-code-preview@10.1.1

Malicious code in vl-ui-code-preview (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package impersonating the Flemish government's @govflanders/vl-ui-code-preview library. The unscoped vl-ui-code-preview@10.1.1 ships a 55-byte placeholder index.js with no functional code. Both preinstall and postinstall hooks execute curl commands that exfiltrate system metadata (username via whoami, hostname, current working directory, and current timestamp) to the external endpoint hxxps://178fx66q[.]instances[.]httpworkbench[.]com/depconf/. The URL path /depconf/ and parameters (pkg, u, h, d, t) indicate targeted dependency-confusion reconnaissance measuring which environments are susceptible to the attack.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:13 PM
analyzed
Jun 15, 2026, 09:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.