LWA-2026-5459 confirmed malware

vui-gateway@45.0.0

Malicious code in vui-gateway (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Dependency-confusion package squatting an internal/private package name. The package declares a self-referencing dependency pointing to an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/vui-gateway). When npm resolves this non-registry dependency, it fetches a tarball from the remote host (repo[.]securityctrl[.]com), enabling the attacker to serve arbitrary malicious content at install time. The published package itself is a minimal 532-byte stub with placeholder code, indicating the dependency URL is the intended payload delivery channel.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 10:59 PM
analyzed
Jun 15, 2026, 11:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.