LWA-2026-11095 confirmed malware

buildifier@1.0.0

Malicious code in buildifier (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

buildifier@1.0.0 ships a postinstall lifecycle hook that executes a bundled postinstall.js script on install, alongside a noop.js bin entry. The package describes itself as a security-research canary but provides no verifiable research provenance (no repository or program reference), and the install-time hook runs bundled code. The tarball was removed from the registry before source-level analysis could be completed, so this advisory is based on the published manifest metadata.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 04:59 PM
analyzed
Aug 12, 2026, 05:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.