@devmikets/hyperliquid-sdk@1.9.5
Malicious code in @devmikets/hyperliquid-sdk (npm)
Analysis
@devmikets/hyperliquid-sdk@1.9.5 declares a dependency on "typescript-eslint" resolved from the raw URL hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz — a lookalike of the official npm registry host registry[.]npmjs[.]org. Because the dependency is specified as a direct tarball URL rather than a registry version range, npm downloads and unpacks the attacker-controlled archive from registrynpmjs.to during install, executing whatever that archive contains in the installer's environment. The package itself ships no lifecycle hook and no obfuscated code; the entire attack is the dependency redirect, which is easy to miss because the package otherwise presents as a normal Hyperliquid exchange SDK (combosquat on the real Hyperliquid SDK name, with repository and homepage pointing at github[.]com/devmikets/hyperliquid-sdk). Any project that installs this version pulls code from the lookalike registry domain.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 12:17 AM
- analyzed
- Oct 8, 2026, 12:16 PM
Related advisories
- @devmikets/hyperliquid-sdk@1.9.1 same package
- @devmikets/hyperliquid-sdk@1.9.2 same package
- @devmikets/hyperliquid-sdk@1.9.3 same package
- @devmikets/hyperliquid-sdk@1.9.4 same package
- @devmikets/hyperliquid-sdk@1.9.6 same package
- chai-as-indexed@6.0.5
- tensorlake@0.5.144
- dzyclutch-baileys@1.1.21
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.