LWA-2026-10641 confirmed malware

@morpho-blue-liquidation-bot/liquidity-venues@2.0.0

Malicious code in @morpho-blue-liquidation-bot/liquidity-venues (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package declares a dependency on itself resolved from the non-registry HTTP host pack[.]nppacks[.]com (hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-liquidation-bot/liquidity-venues) in both dependencies and devDependencies. Installing the package causes npm to fetch the self-dependency from that external host over plain HTTP, meaning the code actually executed is served from a non-standard third-party registry rather than the npm registry. The package name impersonates the Morpho Blue DeFi protocol's liquidation-bot tooling.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:55 PM
analyzed
Aug 6, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.