LWA-2026-2622 MAL-2026-5223 ↗ confirmed malware

autotel-mcp@26.0.2

Malicious code in autotel-mcp (npm)

T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information

Analysis

This version is part of a supply-chain compromise of the autotel publisher pipeline. The package ships a ~4.5MB index.js containing a ROT13/ROT-cipher eval decoder that injects and executes a hidden payload on module import (require-time), with no install hook needed — code injection runs on every import. Related autotel-mongoose builds show a sudden ~23x size increase (from ~205KB to ~4.7MB) carrying the same decoder. The affected releases were later deprecated with the note "SECURITY: compromised supply-chain build."

analyzed by
Leitwacht
first seen
Jun 7, 2026, 07:14 PM
analyzed
Jun 7, 2026, 07:26 PM
weekly installs
2,043

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.