oit-lib-oracle-util@45.0.0
Malicious code in oit-lib-oracle-util (npm)
Analysis
oit-lib-oracle-util@45.0.0 is a dependency-confusion placeholder whose manifest declares a self-dependency pointing to the attacker-controlled URL hxxps://repo[.]securityctrl[.]com/oit-lib-oracle-util. On install, dependency resolution fetches a tarball from that URL, allowing arbitrary code to be served. The shipped code has no real functionality (a 92-byte index.js that prints a demo message; the README falsely claims to be an anti-dependency-confusion placeholder). The package name mimics an internal/private library while the manifest hijacks resolution to an external server.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 07:30 PM
- analyzed
- Jun 11, 2026, 07:32 PM
Related advisories
- no-date-parsing@2.2.0
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.