LWA-2026-10645 confirmed malware

@vault-v2-reallocation-bot/client@0.0.1

Malicious code in @vault-v2-reallocation-bot/client (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package declares a dependency on itself resolved from a non-registry HTTP host: hxxp://pack[.]nppacks[.]com/npm/@vault-v2-reallocation-bot/client (plain HTTP, no TLS), listed in both dependencies and devDependencies. Installing this package makes the package manager fetch that self-dependency from the external host, which can serve arbitrary code. The bundled code is a Babel plugin unrelated to the package's stated name and purpose.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:55 PM
analyzed
Aug 6, 2026, 05:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.