LWA-2026-5459 confirmed malware
vui-gateway@45.0.0
Malicious code in vui-gateway (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Dependency-confusion package squatting an internal/private package name. The package declares a self-referencing dependency pointing to an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/vui-gateway). When npm resolves this non-registry dependency, it fetches a tarball from the remote host (repo[.]securityctrl[.]com), enabling the attacker to serve arbitrary malicious content at install time. The published package itself is a minimal 532-byte stub with placeholder code, indicating the dependency URL is the intended payload delivery channel.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:59 PM
- analyzed
- Jun 15, 2026, 11:00 PM
Related advisories
- vue-template-compiler-plugin@2.7.16
- vourfly-tele@4.7.6
- vite-enhancer-config@1.2.1
- @httpactions/encode-url@1.0.0
- boardflow@1.1.4
- typescript-util-core@7.1.5
- @sfhbdrffthger/boardstep@1.0.0
- vite-config-field@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.