prm-bundles@45.0.0
Malicious code in prm-bundles (npm)
Analysis
An install-time payload-fetch shell. The manifest declares a self-dependency on its own name at the non-registry URL hxxps://repo[.]securityctrl[.]com/prm-bundles, so installing it causes npm to resolve the package name from that external host and fetch whatever tarball it serves (with attendant lifecycle-hook code execution). The published source is deliberately empty (531 bytes, a trivial console.log, README claiming it is a "placeholder to prevent dependency confusion"), offloading the real payload to install-time dependency resolution from the attacker-controlled host.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 01:59 PM
- analyzed
- Jun 12, 2026, 02:00 PM
Related advisories
- poxios-chain@1.3.5
- polymarket-gamma-api@1.4.9
- polymarket-gamma-apis@1.4.0
- polygon-bitquery-apis@2.2.3
- node-path-utils@1.23.2
- peptideenv@16.6.6
- vite-react-toolkit@1.0.1
- payments-ui-services@45.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.