LWA-2026-4511 confirmed malware

papika-fetcher@1.0.1

Malicious code in papika-fetcher (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

papika-fetcher@1.0.1 declares a circular self-dependency (papika-fetcher:^1.0.0) that disrupts normal npm install. Its main.js fetches remote JavaScript from raw[.]githubusercontent[.]com/AD-CHII/TrueCHII-GIFT/main/index.js, writes it locally, and then require()s it to load and execute the fetched code. There are no lifecycle hooks, so the code runs only when explicitly called, but the self-dependency plus remote-code fetch-and-execute is a clear supply-chain attack pattern.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 12:59 AM
analyzed
Jun 12, 2026, 01:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.