LWA-2026-10494 confirmed malware

@dexwilt/mf-node@2.7.46

Malicious code in @dexwilt/mf-node (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

A clone of the module-federation Node runtime published under the scoped name @dexwilt/mf-node. Its package.json substitutes the standard node-fetch dependency with the alias npm:@glitchpad/node-fetch@2.7.2, a package that is not present in the public npm registry — a dependency-substitution vector that would install attacker-controlled code (including any install scripts) if that package were published. The bundled runtime fetches and eval-executes remote chunk code from configured federation hosts.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 02:09 PM
analyzed
Aug 5, 2026, 04:49 PM
weekly installs
65

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.