@sqlite-node/createsql@1.0.9
Malicious code in @sqlite-node/createsql (npm)
Analysis
This package advertises itself as a SQLite toolkit but contains no SQLite functionality. Its main module fetches a hardcoded remote GitHub gist over HTTPS, extracts the contents of the first file in that gist, and passes it directly to eval(), executing attacker-controlled JavaScript whenever the module is loaded. The remotely-hosted payload can be changed by the attacker at any time, making it a remote-code-execution loader/dropper.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 03:29 PM
- analyzed
- Jun 28, 2026, 06:35 AM
- weekly installs
- 742
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.