LWA-2026-4018 MAL-2026-5260 ↗ confirmed malware

mountly@0.2.2

Malicious code in mountly (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File

Analysis

A legitimate web-widget scaffold whose published index.js was replaced with an obfuscated injection artifact: a ROT-cipher eval decoder wrapping a large char-code array, with no readable JS outside the decoder. The eval is buggy (Array.prototype.replace throws TypeError), leaving this particular payload inert, but the obfuscated eval-decoder is a clear marker of a compromised, worm-injected publish.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 08:46 PM
analyzed
Jun 10, 2026, 08:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.