LWA-2026-10934 confirmed malware
@sqlite-labs/createsql@1.0.1
Malicious code in @sqlite-labs/createsql (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The package's main entry point (index.js) fetches a remote script from hxxps://bdmkaoyijqmqa6bg[.]public[.]blob[.]vercel-storage[.]com/script[.]js and executes it with eval() on require. The remote payload is attacker-controlled and served from Vercel blob storage; the package is a remote-code-execution dropper with no other functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 05:55 PM
- analyzed
- Aug 10, 2026, 05:56 PM
Related advisories
- @sqlite-labs/nodesql@1.0.5
- chai-as-reformed@1.2.0
- dayjs-advanced@1.2.0
- commonjs-assertion@1.2.7
- polymarket-stake-mathss@3.5.2
- runtimekit@1.1.0
- hex-encode-utils@1.0.5
- @noobaihome/amis-uni-area-widget@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.