LWA-2026-10640 confirmed malware
@morpho-blue-liquidation-bot/data-providers@2.0.0
Malicious code in @morpho-blue-liquidation-bot/data-providers (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
The package's manifest declares a dependency on itself resolved from the non-registry host hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-liquidation-bot/data-providers (in both dependencies and devDependencies). Installing the package therefore fetches its own tarball from that external host over plain HTTP instead of the npm registry, allowing the host to control the code that is installed. The bundled index.js is a Babel DefinePlugin-style plugin; the risk is the self-referential external-host dependency, not the shipped source.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 05:55 PM
- analyzed
- Aug 6, 2026, 05:56 PM
Related advisories
- @morpho-blue-liquidation-bot/liquidity-venues@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- @morpho-blue-liquidation-bot/config@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.