LWA-2026-5441 confirmed malware

vl-ui-contact-card@10.1.1

Malicious code in vl-ui-contact-card (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

vl-ui-contact-card@10.1.1 is a dependency-confusion reconnaissance beacon. Both preinstall and postinstall lifecycle hooks run curl to exfiltrate host metadata — username (whoami), hostname, current working directory, and timestamp — to the remote host 178fx66q[.]instances[.]httpworkbench[.]com via the URL path /depconf/. The package contains no functional code: index.js is a single-line comment stub. The description "A simple, benign placeholder for npm." and the || true error suppression are designed to mask the recon activity and silently succeed regardless of network failure.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:13 PM
analyzed
Jun 15, 2026, 09:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.