LWA-2026-10644 confirmed malware

@pump-fun-skills/coin-fees@1.0.0

Malicious code in @pump-fun-skills/coin-fees (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package declares a dependency on itself resolved from a non-registry external host (hxxp://pack[.]nppacks[.]com/npm/@pump-fun-skills/coin-fees) in both dependencies and devDependencies. Installing the package causes npm to fetch a tarball from that external host, which is attacker-controllable and can substitute a malicious payload. The bundled code is a Babel plugin for inlining environment variables; the supply-chain risk is the external-host self-dependency in the manifest.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:55 PM
analyzed
Aug 6, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.