warp-dependency@1.0.0
Malicious code in warp-dependency (npm)
Analysis
warp-dependency@1.0.0 is a supply-chain attack package. Its postinstall hook runs an obfuscated JavaScript payload that downloads a Windows executable (bss.exe) from a Cloudflare tunnel (recorder-our-betting-chair[.]trycloudflare[.]com/page) using node-fetch, writes it to disk with fs-extra, and executes it via child_process.exec. The package declares sudo-prompt as a dependency (elevation), the publisher uses a throwaway Gmail address, and the description ("Mac UI for Windows Toolkit") is nonsensical. The binary served from the tunnel could perform credential theft, backdoor access, or lateral movement as a second-stage payload.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 11:08 PM
- analyzed
- Jun 12, 2026, 11:09 PM
Related advisories
- openclaw-preview@2026.6.1
- vite-tsconfig@1.1.2
- express-initial@12.1.7
- node-pino@2.3.2
- linux-ci-utils@1.0.0
- mountly@0.2.2
- mountly-tailwind@0.1.3
- postcss-processor-utils@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.