LWA-2026-10669 confirmed malware

@vertexa/prisma-engines@7.8.1

Malicious code in @vertexa/prisma-engines (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

@vertexa/prisma-engines is a combosquat of Prisma's @prisma/engines package. Its postinstall hook downloads the "Prisma engine" binary from an attacker-controlled GitHub fork (github[.]com/lh0x00/prisma/releases/download/engines-b436f5b358bf3b9d72861631111333dd40434f73) instead of the official Prisma binaries host, and executes the downloaded binary at install time. The attacker controls the binary that is fetched and run on every install.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 04:34 AM
analyzed
Aug 7, 2026, 04:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.