LWA-2026-5449 confirmed malware

vue-plugin-bomb@1.0.1

Malicious code in vue-plugin-bomb (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1485 · Data DestructionT1529 · System Shutdown/Reboot

Analysis

vue-plugin-bomb@1.0.1 is a destructive wiper. Its index.js imports the npm package 'child_process' (typosquatting the Node.js core module) and uses process.execSync on a timed schedule. During specific date windows (June through September 2023), the code repeatedly executes 'shutdown -s -t 5' to force a system shutdown with 5-second delay. Additionally, on a broader schedule it recursively deletes the following directories and files from the project's node_modules: vue/dist, vue-router/dist, vue-router/index.js, vant/lib, vant/es (Jul-Aug); and pinia/dist, pinia/index.js, vite-plugin-vue-setup-extend/dist, axios/dist, axios/index.js, vite/dist, vite/bin, vite/types, vite/index.js (Sep onward). The package has no legitimate functionality — it is solely a time-bomb wiper targeting Vue/Vite/Axios-based Node.js projects, with no exfiltration or C2.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:43 PM
analyzed
Jun 15, 2026, 10:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.