LWA-2026-10643 confirmed malware

@morpho-blue-reallocation-bot/client@2.0.0

Malicious code in @morpho-blue-reallocation-bot/client (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package manifest declares a dependency on itself resolved from a non-registry HTTP host (hxxp://pack[.]nppacks[.]com/npm/@morpho-blue-reallocation-bot/client) in both dependencies and devDependencies. Installing the package causes npm to fetch and execute code from that external plain-HTTP host, which is attacker-controlled and can serve arbitrary code at install time. The bundled index.js is a benign Babel plugin; the malicious behaviour is the manifest's external-URL dependency resolution.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:55 PM
analyzed
Aug 6, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.