LWA-2026-10494 confirmed malware
@dexwilt/mf-node@2.7.46
Malicious code in @dexwilt/mf-node (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
A clone of the module-federation Node runtime published under the scoped name @dexwilt/mf-node. Its package.json substitutes the standard node-fetch dependency with the alias npm:@glitchpad/node-fetch@2.7.2, a package that is not present in the public npm registry — a dependency-substitution vector that would install attacker-controlled code (including any install scripts) if that package were published. The bundled runtime fetches and eval-executes remote chunk code from configured federation hosts.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 02:09 PM
- analyzed
- Aug 5, 2026, 04:49 PM
- weekly installs
- 65
Related advisories
- devplatform-vite-plugin-preserve-css-modules@35.6.8
- dolyame-boxy-independent-bnpl-mobile-application@35.9.2
- dolyame-boxy-independent-bnpl-main-banner@35.2.1
- dolyame-boxy-independent-bnpl-text-block@35.5.3
- devplatform-nx-devkit@35.8.5
- dolyame-boxy-independent-bnpl-title@35.7.3
- dolyame-boxy-independent-bnpl-table@35.3.4
- delivery-ci-microforms@35.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.