LWA-2026-11095 confirmed malware
buildifier@1.0.0
Malicious code in buildifier (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
buildifier@1.0.0 ships a postinstall lifecycle hook that executes a bundled postinstall.js script on install, alongside a noop.js bin entry. The package describes itself as a security-research canary but provides no verifiable research provenance (no repository or program reference), and the install-time hook runs bundled code. The tarball was removed from the registry before source-level analysis could be completed, so this advisory is based on the published manifest metadata.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 04:59 PM
- analyzed
- Aug 12, 2026, 05:02 PM
Related advisories
- dzvchorehui2@1.0.0
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
- bs58-33@6.0.1
- base65-33x@5.0.2
- neverthrow-core@1.1.2
- base65-15x@5.0.2
- base65-77x@5.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.