@devmikets/hyperliquid-sdk@1.9.3
Malicious code in @devmikets/hyperliquid-sdk (npm)
Analysis
@devmikets/hyperliquid-sdk versions 1.9.1 through 1.9.5 declare a runtime dependency on a tarball hosted outside the npm registry: dependencies.typescript-eslint is pinned to the literal URL hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz. registrynpmjs.to is a look-alike host, not the npm registry, so installing the package causes npm to download and unpack a third-party tarball from that origin — the code that ends up in node_modules is whatever that host serves, not the code published to npm. The package itself ships no install hook and its published files are a clean-looking Hyperliquid trading SDK (API client, EIP-712 signing helpers, viem/ethers examples), which is what makes the dependency spec the whole attack: the published bytes are benign while the install pulls code from a non-registry origin. The name mimics the legitimate Hyperliquid SDK package @nktkas/hyperliquid, and the declared GitHub repository does not resolve. No other non-registry endpoints, credential reads, or obfuscated payloads were found in the tarball.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 12:16 AM
- analyzed
- Oct 8, 2026, 12:23 PM
Related advisories
- @devmikets/hyperliquid-sdk@1.9.1 same package
- @devmikets/hyperliquid-sdk@1.9.2 same package
- @devmikets/hyperliquid-sdk@1.9.5 same package
- @devmikets/hyperliquid-sdk@1.9.4 same package
- @devmikets/hyperliquid-sdk@1.9.6 same package
- @polymarkets/clob-client-v2@1.0.3
- neverthrow-js@4.5.1
- @polymarkets/clob-client-v2@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.