LWA-2026-10949 confirmed malware

@sqlite-labs-free/createsql@1.0.5

Malicious code in @sqlite-labs-free/createsql (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

On require, the package fetches a remote JavaScript payload from hxxps://bdmkaoyijqmqa6bg[.]public[.]blob[.]vercel-storage[.]com/script[.]js and executes it with eval(). The fetched script is attacker-controlled and served from Vercel blob storage; the package itself contains no other code or functionality. Any code in the remote payload runs with the privileges of the importing process.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 03:39 AM
analyzed
Aug 11, 2026, 03:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.