vl-ui-contact-card@10.1.1
Malicious code in vl-ui-contact-card (npm)
Analysis
vl-ui-contact-card@10.1.1 is a dependency-confusion reconnaissance beacon. Both preinstall and postinstall lifecycle hooks run curl to exfiltrate host metadata — username (whoami), hostname, current working directory, and timestamp — to the remote host 178fx66q[.]instances[.]httpworkbench[.]com via the URL path /depconf/. The package contains no functional code: index.js is a single-line comment stub. The description "A simple, benign placeholder for npm." and the || true error suppression are designed to mask the recon activity and silently succeed regardless of network failure.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:13 PM
- analyzed
- Jun 15, 2026, 09:13 PM
Related advisories
- @dilxzphrine/libsignal-node@2.5.0
- @sfhbdrffthger/boardstep@1.0.0
- vite-config-field@1.1.0
- dms-backend@1.0.0
- ts-webplug@3.0.5
- tsliverhome@1.1.5
- trgrip@1.0.4
- transform-es2015-destructuring@6.24.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.