LWA-2026-10639 confirmed malware

@morpho-blue-liquidation-bot/config@2.0.0

Malicious code in @morpho-blue-liquidation-bot/config (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScript

Analysis

The package declares a dependency on itself resolved from a non-registry HTTP host (hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-liquidation-bot/config) in both dependencies and devDependencies. At install time npm fetches the tarball from that attacker-controlled plaintext HTTP server and executes its contents, giving the remote host arbitrary code execution on the installer's machine. The package name impersonates a DeFi liquidation-bot project. The bundled index.js is a benign babel plugin; the malicious behaviour is the external self-dependency that pulls and runs code from pack[.]nppacks[.]com.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:55 PM
analyzed
Aug 6, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.