LWA-2026-10852 confirmed malware

@devmikets/hyperliquid-sdk@1.9.6

Malicious code in @devmikets/hyperliquid-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package declares a dependency on the well-known 'inquirer' package but resolves it from a typosquatted registry host (registrynpmjs.to) instead of the official npm registry, fetching the tarball from hxxps://registrynpmjs[.]to/inquirer-14[.]0[.]2[.]tgz. The inquirer dependency is never imported or used anywhere in the package's source, indicating it is an injected dependency whose tarball is served from a non-official, lookalike domain. Installing this package would pull the inquirer tarball from that attacker-controlled host.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 10:56 PM
analyzed
Aug 8, 2026, 10:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.