prettier_v1@3.8.4
Malicious code in prettier_v1 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1564.003 · Hidden Window
Analysis
Multi-stage dropper combosquatting the prettier formatter: prettier_v1@3.8.4. On install, node cli.js runs and chains to lib/mirror.js, which base64-decodes a remote URL (hxxps://api[.]aavcareer[.]ink/install_guard[.]js), fetches it over HTTPS with rejectUnauthorized:false, and spawns it in a hidden detached node process (windowsHide:true, unref'd) to evade detection. CI/ignore-scripts guard conditions in the code show adversarial awareness.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:44 AM
- analyzed
- Jun 10, 2026, 10:45 AM
Related advisories
- optional-cpu-features@1.0.3
- dolyame-ui-tooltip@35.8.8
- fdd41@1.0.0
- express-dever@5.1.7
- @asyncapi/specs@6.11.2
- @asyncapi/generator-helpers@1.1.1
- express-ini@12.1.10
- mailconfirmer@3.3.21
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.