LWA-2026-12686 confirmed malware

@devmikets/hyperliquid-sdk@1.9.5

Malicious code in @devmikets/hyperliquid-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter

Analysis

@devmikets/hyperliquid-sdk@1.9.5 declares a dependency on "typescript-eslint" resolved from the raw URL hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz — a lookalike of the official npm registry host registry[.]npmjs[.]org. Because the dependency is specified as a direct tarball URL rather than a registry version range, npm downloads and unpacks the attacker-controlled archive from registrynpmjs.to during install, executing whatever that archive contains in the installer's environment. The package itself ships no lifecycle hook and no obfuscated code; the entire attack is the dependency redirect, which is easy to miss because the package otherwise presents as a normal Hyperliquid exchange SDK (combosquat on the real Hyperliquid SDK name, with repository and homepage pointing at github[.]com/devmikets/hyperliquid-sdk). Any project that installs this version pulls code from the lookalike registry domain.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 12:17 AM
analyzed
Oct 8, 2026, 12:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.