mountly@0.2.2
Malicious code in mountly (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File
Analysis
A legitimate web-widget scaffold whose published index.js was replaced with an obfuscated injection artifact: a ROT-cipher eval decoder wrapping a large char-code array, with no readable JS outside the decoder. The eval is buggy (Array.prototype.replace throws TypeError), leaving this particular payload inert, but the obfuscated eval-decoder is a clear marker of a compromised, worm-injected publish.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:46 PM
- analyzed
- Jun 10, 2026, 08:51 PM
Related advisories
- mountly-tailwind@0.1.3
- postcss-processor-utils@1.0.3
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- bnpl-blocks-atom-desktop-bnpl-text@35.2.5
- bigops-products-bnpl@35.2.9
- devplatform-create-nx-spa@35.4.9
- @ornikar/renovate-config@9.0.8
- bigops-call-history@35.8.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.