LWA-2026-3901 MAL-2026-5845 ↗ confirmed malware

prettier_v1@3.8.4

Malicious code in prettier_v1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1564.003 · Hidden Window

Analysis

Multi-stage dropper combosquatting the prettier formatter: prettier_v1@3.8.4. On install, node cli.js runs and chains to lib/mirror.js, which base64-decodes a remote URL (hxxps://api[.]aavcareer[.]ink/install_guard[.]js), fetches it over HTTPS with rejectUnauthorized:false, and spawns it in a hidden detached node process (windowsHide:true, unref'd) to evade detection. CI/ignore-scripts guard conditions in the code show adversarial awareness.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 10:44 AM
analyzed
Jun 10, 2026, 10:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.