LWA-2026-10075 confirmed malware
de-morgan@2.1.3
Malicious code in de-morgan (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
The package declares a dependency on itself resolved from a non-registry HTTP URL (hxxp://pack[.]nppacks[.]com/npm/de-morgan). Installing it makes npm fetch the de-morgan tarball over plain HTTP from this third-party host instead of the npm registry, so whatever is served at that URL is installed and executed as part of the dependency tree. The bundled index.js is a Babel environment-variable replacement plugin with no payload of its own; the malicious vector is the dependency redirect to the non-registry host.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 07:28 PM
- analyzed
- Aug 4, 2026, 07:29 PM
Related advisories
- vitest-preview-pro@10.0.3
- @tuluax/errb@3.0.1
- @or-sdk/base@0.44.6
- @or-sdk/sdk-api@0.29.4
- @onereach/ui-components@27.0.4
- @onereach/ui-components-vue2@27.0.4
- @or-sdk/providers@0.3.8
- @or-sdk/event-manager@1.1.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.