LWA-2026-10076 MAL-2026-13612 ↗ confirmed malware

transform-es2015-unicode-regex@6.24.1

Malicious code in transform-es2015-unicode-regex (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package impersonates the real Babel plugin transform-es2015-unicode-regex but declares a self-dependency resolved from a non-registry plain-HTTP host: hxxp://pack[.]nppacks[.]com/npm/transform-es2015-unicode-regex (also listed in devDependencies). Installing the package causes npm to fetch this self-dependency from the attacker-controlled server over unencrypted HTTP and install whatever it serves, enabling arbitrary code execution at install time. The bundled index.js is a benign Babel plugin used as a decoy; the malicious behaviour is the dependency spec redirecting resolution to the external host.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 07:37 PM
analyzed
Aug 4, 2026, 07:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.