LWA-2026-4396 confirmed malware

oit-lib-oracle-util@45.0.0

Malicious code in oit-lib-oracle-util (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

oit-lib-oracle-util@45.0.0 is a dependency-confusion placeholder whose manifest declares a self-dependency pointing to the attacker-controlled URL hxxps://repo[.]securityctrl[.]com/oit-lib-oracle-util. On install, dependency resolution fetches a tarball from that URL, allowing arbitrary code to be served. The shipped code has no real functionality (a 92-byte index.js that prints a demo message; the README falsely claims to be an anti-dependency-confusion placeholder). The package name mimics an internal/private library while the manifest hijacks resolution to an external server.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 07:30 PM
analyzed
Jun 11, 2026, 07:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.