LWA-2026-4405 confirmed malware

one-intuit-help-system-utils@45.0.0

Malicious code in one-intuit-help-system-utils (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScript

Analysis

one-intuit-help-system-utils@45.0.0 declares a self-dependency pointing to the non-registry external URL hxxps://repo[.]securityctrl[.]com/one-intuit-help-system-utils. When npm resolves this dependency it fetches a tarball from that attacker-controlled host, and any lifecycle scripts in the fetched payload execute on the installer's machine. The shipped index.js is inert (a benign log message), consistent with a staged attack where the real payload is served externally rather than shipped in the tarball.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 08:15 PM
analyzed
Jun 11, 2026, 08:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.