LWA-2026-10644 confirmed malware
@pump-fun-skills/coin-fees@1.0.0
Malicious code in @pump-fun-skills/coin-fees (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package declares a dependency on itself resolved from a non-registry external host (hxxp://pack[.]nppacks[.]com/npm/@pump-fun-skills/coin-fees) in both dependencies and devDependencies. Installing the package causes npm to fetch a tarball from that external host, which is attacker-controllable and can substitute a malicious payload. The bundled code is a Babel plugin for inlining environment variables; the supply-chain risk is the external-host self-dependency in the manifest.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 05:55 PM
- analyzed
- Aug 6, 2026, 05:56 PM
Related advisories
- @morpho-blue-liquidation-bot/pricers@2.0.0
- @morpho-blue-liquidation-bot/config@2.0.0
- @morpho-blue-reallocation-bot/client@2.0.0
- mnchfnvbue1@1.0.0
- clients-structure@35.9.8
- constructor-blocks-landings@35.5.7
- hardhat-set@2.21.0
- npm-dc-dev@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.