mountly@0.2.2
Malicious code in mountly (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File
Analysis
A legitimate web-widget scaffold whose published index.js was replaced with an obfuscated injection artifact: a ROT-cipher eval decoder wrapping a large char-code array, with no readable JS outside the decoder. The eval is buggy (Array.prototype.replace throws TypeError), leaving this particular payload inert, but the obfuscated eval-decoder is a clear marker of a compromised, worm-injected publish.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:46 PM
- analyzed
- Jun 10, 2026, 08:51 PM
Related advisories
- mountly-tailwind@0.1.3
- postcss-processor-utils@1.0.3
- nebulaai-sdk@1.0.0
- chromatitle@1.0.0
- @syncraft-labs/vue@0.4.1
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- @wizloft/harness@0.1.1-alpha.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.