transform-es2015-unicode-regex@6.24.1
Malicious code in transform-es2015-unicode-regex (npm)
Analysis
The package impersonates the real Babel plugin transform-es2015-unicode-regex but declares a self-dependency resolved from a non-registry plain-HTTP host: hxxp://pack[.]nppacks[.]com/npm/transform-es2015-unicode-regex (also listed in devDependencies). Installing the package causes npm to fetch this self-dependency from the attacker-controlled server over unencrypted HTTP and install whatever it serves, enabling arbitrary code execution at install time. The bundled index.js is a benign Babel plugin used as a decoy; the malicious behaviour is the dependency spec redirecting resolution to the external host.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 07:37 PM
- analyzed
- Aug 4, 2026, 07:38 PM
Related advisories
- de-morgan@2.1.3
- vitest-preview-pro@10.0.3
- @tuluax/errb@3.0.1
- @or-sdk/base@0.44.6
- @or-sdk/sdk-api@0.29.4
- @onereach/ui-components@27.0.4
- @onereach/ui-components-vue2@27.0.4
- @or-sdk/providers@0.3.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.