LWA-2026-4405 confirmed malware
one-intuit-help-system-utils@45.0.0
Malicious code in one-intuit-help-system-utils (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScript
Analysis
one-intuit-help-system-utils@45.0.0 declares a self-dependency pointing to the non-registry external URL hxxps://repo[.]securityctrl[.]com/one-intuit-help-system-utils. When npm resolves this dependency it fetches a tarball from that attacker-controlled host, and any lifecycle scripts in the fetched payload execute on the installer's machine. The shipped index.js is inert (a benign log message), consistent with a staged attack where the real payload is served externally rather than shipped in the tarball.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 08:15 PM
- analyzed
- Jun 11, 2026, 08:16 PM
Related advisories
- internallib_v856@99.0.0
- params-valid-js@1.0.3
- @genie-auth/config@99.9.1
- vite-tsconfig@1.1.2
- chalk-plus-ts@1.0.3
- bubblestring@1.1.4
- npm-doc-dev@1.0.9
- chalk-plus-js@7.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.