LWA-2026-11643 confirmed malware

external_deps_enjoyer@1.0.0

Malicious code in external_deps_enjoyer (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package ships no code; its manifest alone is the payload. It declares dependencies that resolve to attacker-controlled external tarballs and git repositories over non-registry protocols, so installing it makes npm fetch and execute remote payloads from those hosts. Dependency specs point at cdn[.]discordapp[.]com/attachments/.../runtime.tgz, hxxp://203[.]0[.]113[.]77:8443/drop/pkg[.]tgz, hxxp://198[.]51[.]100[.]44/hidden/pkg[.]tgz, git+ssh://[account]/tmp-drop-8821/node-helper.git, git+hxxps://gitlab[.]com/anon-x7k2/sys-update[.]git, git://203[.]0[.]113[.]91/hidden/repo.git, git+ssh://[account]/throwaway-drop/payload.git, gist:c0ffee00deadbeef, hxxps://webhook[.]site/00000000-0000-4000-8000-000000000000/pkg[.]tgz, hxxp://interact[.]sh/stage2/nested[.]tgz, hxxps://rentry[.]co/faketestpoc/raw, and hxxps://abc123xyz[.]ngrok-free[.]app/pkg[.]tgz, plus local file/link/portal paths under /tmp and ~/.config. The dependency graph is designed to pull remote code from these hosts at install time.

analyzed by
Leitwacht
first seen
Aug 26, 2026, 01:43 PM
analyzed
Aug 26, 2026, 01:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.