search-reservation@55.0.0
Malicious code in search-reservation (npm)
Analysis
package search-reservation@55.0.0 performs a dependency-confusion attack using a self-referencing external dependency. Its manifest declares the dependency "search-reservation" pointing to the attacker-controlled URL hxxps://repo[.]securityctrl[.]com/search-reservation. When npm installs this package, the package manager resolves the self-dependency by downloading and installing a tarball from that external URL, allowing the attacker to serve arbitrary code onto the installer's system. The shipped index.js is an inert 92-byte stub that logs a benign message; the entire malicious mechanism operates at the manifest/metadata layer via the external dependency resolution.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 04:17 PM
- analyzed
- Jun 13, 2026, 04:19 PM
Related advisories
- rollup-runtime-polyfill-core@0.13.5
- rollup-packages-polyfill-core@0.5.0
- rollup-plugin-polyfill-connect@1.0.1
- ring-device-settings-library@45.0.0
- request-js-validator@1.0.2
- macos-ci-utils@1.0.1
- redirect-azlazy@1.0.0
- redeem-onchain-sdk@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.