LWA-2026-4762 confirmed malware

prm-bundles@45.0.0

Malicious code in prm-bundles (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

An install-time payload-fetch shell. The manifest declares a self-dependency on its own name at the non-registry URL hxxps://repo[.]securityctrl[.]com/prm-bundles, so installing it causes npm to resolve the package name from that external host and fetch whatever tarball it serves (with attendant lifecycle-hook code execution). The published source is deliberately empty (531 bytes, a trivial console.log, README claiming it is a "placeholder to prevent dependency confusion"), offloading the real payload to install-time dependency resolution from the attacker-controlled host.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 01:59 PM
analyzed
Jun 12, 2026, 02:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.