autotel-mongoose@0.0.3
Malicious code in autotel-mongoose (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
This version is part of a supply-chain compromise of the autotel publisher pipeline. The release shows a sudden ~23x size increase (from ~205KB to ~4.7MB) carrying a ROT13/ROT-cipher eval decoder that injects and executes a hidden payload on module import (require-time), with no install hook needed. The affected releases were later deprecated with the note "SECURITY: compromised supply-chain build."
- analyzed by
- Leitwacht
- first seen
- Jun 7, 2026, 07:17 PM
- analyzed
- Jun 7, 2026, 07:26 PM
- weekly installs
- 1,176
Related advisories
- autotel-mongoose@2.0.5 same package
- autotel-mongoose@3.0.1 same package
- autotel-mongoose@6.0.1 same package
- autotel-mongoose@4.0.1 same package
- ai-sdk-helpers@1.3.1
- ai-sdk-helpers@0.1.0
- ai-sdk-helpers@0.1.1
- ai-sdk-helpers@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.