LWA-2026-10852 confirmed malware
@devmikets/hyperliquid-sdk@1.9.6
Malicious code in @devmikets/hyperliquid-sdk (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
The package declares a dependency on the well-known 'inquirer' package but resolves it from a typosquatted registry host (registrynpmjs.to) instead of the official npm registry, fetching the tarball from hxxps://registrynpmjs[.]to/inquirer-14[.]0[.]2[.]tgz. The inquirer dependency is never imported or used anywhere in the package's source, indicating it is an injected dependency whose tarball is served from a non-official, lookalike domain. Installing this package would pull the inquirer tarball from that attacker-controlled host.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 10:56 PM
- analyzed
- Aug 8, 2026, 10:56 PM
Related advisories
- kit-map-streak@1.0.0
- wsallin@1.0.0
- @opezneppelin/contracts@5.0.2
- @rblxts/services@1.6.0
- @ethers-js/contracts@6.9.0
- @solana-js/web3@1.91.3
- @reducers/projects@99.9.1
- specials-resources-server@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.