LWA-2026-10669 confirmed malware
@vertexa/prisma-engines@7.8.1
Malicious code in @vertexa/prisma-engines (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
@vertexa/prisma-engines is a combosquat of Prisma's @prisma/engines package. Its postinstall hook downloads the "Prisma engine" binary from an attacker-controlled GitHub fork (github[.]com/lh0x00/prisma/releases/download/engines-b436f5b358bf3b9d72861631111333dd40434f73) instead of the official Prisma binaries host, and executes the downloaded binary at install time. The attacker controls the binary that is fetched and run on every install.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 04:34 AM
- analyzed
- Aug 7, 2026, 04:35 AM
Related advisories
- internallib_v514@1.0.1
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- express-chai@3.7.9
- @vault-v2-reallocation-bot/client@0.0.1
- @morpho-blue-liquidation-bot/liquidity-venues@2.0.0
- @morpho-blue-liquidation-bot/config@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.