prettier-lint-lenz@2.6.4
Malicious code in prettier-lint-lenz (npm)
Analysis
Combosquat of the 'prettier' code formatter (package name 'prettier-lint-lenz', publisher [account]). The postinstall hook copies bundled payload files to %LOCALAPPDATA%\prettier-lint, then runs ctll.mjs which creates a Windows scheduled task 'CdllProtect' that persists across reboots. The payload cdll.mjs polls the Windows clipboard every 250ms and POSTs its contents to hxxp://204[.]10[.]194[.]64:5000/api/nonce — a clipboard-monitoring data exfiltration implant. Also sends an 'installed' beacon at install time to the same C2. No token-theft markers found, but clipboard exfil and persistence alone are a clear supply-chain attack.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 12:30 PM
- analyzed
- Jun 12, 2026, 12:31 PM
Related advisories
- hex-type@3.0.2
- os-ulid-void@3.0.2
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.