@vault-v2-reallocation-bot/config@0.0.1
Malicious code in @vault-v2-reallocation-bot/config (npm)
Analysis
The package manifest declares a dependency on its own package name resolved from a non-registry plain-HTTP host: dependencies["@vault-v2-reallocation-bot/config"] = "hxxp://pack[.]nppacks[.]com/npm/@vault-v2-reallocation-bot/config" (also in devDependencies). Installing the package redirects dependency resolution to that external host over unencrypted HTTP, allowing the host to serve arbitrary code as the dependency. The bundled index.js is a copy of the babel-plugin-transform-define Babel plugin; the supply-chain risk is the external self-dependency URL, not the shipped code.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 05:56 PM
- analyzed
- Aug 6, 2026, 05:57 PM
Related advisories
- @vault-v2-reallocation-bot/client@0.0.1
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/liquidity-venues@2.0.0
- @pump-fun-skills/coin-fees@1.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- @morpho-blue-liquidation-bot/config@2.0.0
- @morpho-blue-reallocation-bot/client@2.0.0
- mnchfnvbue1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.