neverthrow-js@4.5.1
Malicious code in neverthrow-js (npm)
Analysis
neverthrow-js is a combosquat impersonation of the legitimate `neverthrow` library (upstream project supermacro/neverthrow). Version 4.5.1 ships a verbatim copy of the upstream source tree — README.md, LICENSE, dist/index.cjs.js, dist/index[.]es.js and dist/index.d.ts are unchanged from the real project, down to the upstream author's sponsorship and wiki links — while the package name, the `author` field and the `repository` field have been swapped. The repository field points at github[.]com/neverthrow-js/neverthrow, an organisation that does not host the genuine project, so the metadata falsely presents the package as the upstream library. The version number 4.5.1 is an old upstream release number, which makes the package look established. Earlier releases published under this name have been used to distribute malicious code. This particular version contains no install-time payload: there is no preinstall/postinstall hook, no bin entry, no child_process or network call, no eval/atob, no environment or credential reads, and no obfuscation. There is therefore no C2 host, IP, URL path or dropped-file artifact to report for 4.5.1 — the risk is the impersonation of a widely used error-handling library and the package name's history, not code executed on install. Consumers who depend on `neverthrow` should install the genuine package from the supermacro/neverthrow repository rather than this lookalike name.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 02:43 AM
- analyzed
- Oct 8, 2026, 12:19 PM
Related advisories
- neverthrow-js@2.0.0 same package
- @polymarkets/clob-client-v2@1.0.4
- @devmikets/hyperliquid-sdk@1.9.4
- @praveenvjpm/color-utils-7210@1.0.0
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- @pinecone-experience/messages@99.9.1
- solidity-gas-watcher@2.21.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.