LWA-2026-10934 confirmed malware

@sqlite-labs/createsql@1.0.1

Malicious code in @sqlite-labs/createsql (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package's main entry point (index.js) fetches a remote script from hxxps://bdmkaoyijqmqa6bg[.]public[.]blob[.]vercel-storage[.]com/script[.]js and executes it with eval() on require. The remote payload is attacker-controlled and served from Vercel blob storage; the package is a remote-code-execution dropper with no other functionality.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 05:55 PM
analyzed
Aug 10, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.