LWA-2026-10642 confirmed malware
@morpho-blue-liquidation-bot/pricers@2.0.0
Malicious code in @morpho-blue-liquidation-bot/pricers (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
The package manifest declares a dependency (and devDependency) on the package itself, resolved from the non-registry host hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-liquidation-bot/pricers over plaintext HTTP. Installing the package causes npm to fetch that dependency from the external host, which can serve arbitrary code in place of the package. The bundled source is a copy of the babel-plugin-transform-define plugin; the supply-chain risk is the manifest's self-dependency to the external HTTP registry host pack[.]nppacks[.]com.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 05:55 PM
- analyzed
- Aug 6, 2026, 05:56 PM
Related advisories
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/liquidity-venues@2.0.0
- @morpho-blue-liquidation-bot/config@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.