LWA-2026-4511 confirmed malware
papika-fetcher@1.0.1
Malicious code in papika-fetcher (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
papika-fetcher@1.0.1 declares a circular self-dependency (papika-fetcher:^1.0.0) that disrupts normal npm install. Its main.js fetches remote JavaScript from raw[.]githubusercontent[.]com/AD-CHII/TrueCHII-GIFT/main/index.js, writes it locally, and then require()s it to load and execute the fetched code. There are no lifecycle hooks, so the code runs only when explicitly called, but the self-dependency plus remote-code fetch-and-execute is a clear supply-chain attack pattern.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 12:59 AM
- analyzed
- Jun 12, 2026, 01:00 AM
Related advisories
- paper-password-input@45.0.0
- pampipes@1.1.9
- paasprint-sdk@9.9.9
- otto-git-cli@4.0.4
- chai-web3-testkit@1.0.1
- req-parmas-valid@1.0.2
- mddriver@1.8.6
- vite-config-react@1.3.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.