LWA-2026-4776 MAL-2026-5396 ↗ confirmed malware

@sqlite-node/createsql@1.0.9

Malicious code in @sqlite-node/createsql (npm)

Analysis

This package advertises itself as a SQLite toolkit but contains no SQLite functionality. Its main module fetches a hardcoded remote GitHub gist over HTTPS, extracts the contents of the first file in that gist, and passes it directly to eval(), executing attacker-controlled JavaScript whenever the module is loaded. The remotely-hosted payload can be changed by the attacker at any time, making it a remote-code-execution loader/dropper.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 03:29 PM
analyzed
Jun 28, 2026, 06:35 AM
weekly installs
742

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.