LWA-2026-10643 confirmed malware
@morpho-blue-reallocation-bot/client@2.0.0
Malicious code in @morpho-blue-reallocation-bot/client (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
The package manifest declares a dependency on itself resolved from a non-registry HTTP host (hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-reallocation-bot/client) in both dependencies and devDependencies. Installing the package causes npm to fetch and execute code from that external plain-HTTP host, which is attacker-controlled and can serve arbitrary code at install time. The bundled index.js is a benign Babel plugin; the malicious behaviour is the manifest's external-URL dependency resolution.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 05:55 PM
- analyzed
- Aug 6, 2026, 05:56 PM
Related advisories
- streak-map-cache@1.0.0
- tsihealth-client@1.0.2
- streak-cache-map@1.0.0
- clients-structure@35.9.8
- cnb-cnb-core@35.2.7
- cobrowsing-cobrowsing-core@35.5.8
- cobrowsing-configs@35.7.5
- cobrowsing-decorators@35.2.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.