LWA-2026-10949 confirmed malware
@sqlite-labs-free/createsql@1.0.5
Malicious code in @sqlite-labs-free/createsql (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
On require, the package fetches a remote JavaScript payload from hxxps://bdmkaoyijqmqa6bg[.]public[.]blob[.]vercel-storage[.]com/script[.]js and executes it with eval(). The fetched script is attacker-controlled and served from Vercel blob storage; the package itself contains no other code or functionality. Any code in the remote payload runs with the privileges of the importing process.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 03:39 AM
- analyzed
- Aug 11, 2026, 03:40 AM
Related advisories
- freeai-proxy@1.0.0
- vexium-kit@2.0.2
- process-live-log@11.5.2
- @sqlite-labs/nodesql@1.0.5
- safe-local-env-loader@1.0.0
- ventra-kit@1.0.2
- @sqlite-labs/createsql@1.0.1
- chai-as-reformed@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.