LWA-2026-10075 confirmed malware

de-morgan@2.1.3

Malicious code in de-morgan (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package declares a dependency on itself resolved from a non-registry HTTP URL (hxxp://pack[.]nppacks[.]com/npm/de-morgan). Installing it makes npm fetch the de-morgan tarball over plain HTTP from this third-party host instead of the npm registry, so whatever is served at that URL is installed and executed as part of the dependency tree. The bundled index.js is a Babel environment-variable replacement plugin with no payload of its own; the malicious vector is the dependency redirect to the non-registry host.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 07:28 PM
analyzed
Aug 4, 2026, 07:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.