prettier_v2@3.8.5
Malicious code in prettier_v2 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1564.003 · Hidden WindowT1036 · Masquerading
Analysis
Multi-stage dropper combosquatting the prettier code formatter: prettier_v2@3.8.5. An install hook (node cli.js) base64-decodes a URL to hxxps://api[.]aavcareer[.]ink/install_guard_alt_d[.]js, fetches it to a temp file, and spawns it as a hidden, detached, unref'd node process (windowsHide:true). The package includes checks to evade CI and ignore-scripts environments. A Shai-Hulud-shaped multi-stage dropper.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 03:12 PM
- analyzed
- Jun 10, 2026, 03:13 PM
Related advisories
- ded-aa-common-ded-aa-common-core@35.1.6
- bnpl-blocks-independent-bnpl-open-api@35.1.2
- bigops-api@35.8.8
- dolyame-ui-loader@35.1.5
- devplatform-spa-plugin-dom-render@35.5.5
- invest-module-cookie@20.8.2
- bnpl-blocks-independent-bnpl-search@20.2.9
- tinkoff-statist-browser-typed-client-investing.product.pulse@20.4.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.