LWA-2026-10642 confirmed malware

@morpho-blue-liquidation-bot/pricers@2.0.0

Malicious code in @morpho-blue-liquidation-bot/pricers (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

The package manifest declares a dependency (and devDependency) on the package itself, resolved from the non-registry host hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-liquidation-bot/pricers over plaintext HTTP. Installing the package causes npm to fetch that dependency from the external host, which can serve arbitrary code in place of the package. The bundled source is a copy of the babel-plugin-transform-define plugin; the supply-chain risk is the manifest's self-dependency to the external HTTP registry host pack[.]nppacks[.]com.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:55 PM
analyzed
Aug 6, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.