LWA-2026-10937 confirmed malware
@sqlite-labs/nodesql@1.0.5
Malicious code in @sqlite-labs/nodesql (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
@sqlite-labs/nodesql is a trojanized clone of the npm `buffer` module. The package's index.js is the verbatim buffer source with an injected `require('@sqlite-labs/createsql')` at the top. That dependency's index.js fetches a remote script from hxxps://bdmkaoyijqmqa6bg[.]public[.]blob[.]vercel-storage[.]com/script[.]js and executes it with eval() at require time, giving the remote script arbitrary code execution in the installer's process.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 06:27 PM
- analyzed
- Aug 10, 2026, 06:27 PM
Related advisories
- @sqlite-labs/createsql@1.0.1
- safe-local-env-loader@1.0.0
- ventra-kit@1.0.2
- chai-as-reformed@1.2.0
- dayjs-advanced@1.2.0
- commonjs-assertion@1.2.7
- polymarket-stake-mathss@3.5.2
- runtimekit@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.