LWA-2026-10815 confirmed malware
gas-diff-core@1.0.1
Malicious code in gas-diff-core (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
gas-diff-core@1.0.1 is a small JavaScript module that parses Foundry gas-report output and compares gas usage between report versions. The package ships no install or lifecycle scripts, performs no network requests, and does not read or transmit credentials, environment variables, or files. It is a pure text-parsing utility with no observable malicious behaviour in its source.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 09:26 PM
- analyzed
- Aug 7, 2026, 09:26 PM
Related advisories
- @coralxyz/anchor@0.30.2
- dolyame-ui-buttonstore@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contenteditable@35.8.1
- dolyame-ui-contextmenusearchable@35.8.1
- dolyame-ui-flatcorners@35.8.1
- dolyame-ui-overridestyles@35.8.1
- dolyame-ui-progressline@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.