sort-destructure-keys@7.9.0
Malicious code in sort-destructure-keys (npm)
Analysis
The package ships only a minimal stub (index.js logs 'Hello, world!') but declares a dependency 'ui-styles-pkg' that resolves from an external non-npm HTTP registry at hxxp://npm[.]jpartifacts[.]com/npm/sort-destructure-keys. This URL appears in both dependencies and devDependencies in package.json. When the package is installed, npm resolves 'ui-styles-pkg' from this attacker-controlled host, which can serve arbitrary code at install time — an artifact-poisoning / dependency-confusion vector. The C2 registry host is npm[.]jpartifacts[.]com (HTTP, port 80).
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 04:04 AM
- analyzed
- Jun 14, 2026, 04:06 AM
Related advisories
- sort-btree@2.1.4
- solana-token-api@1.0.0
- solanarpclampweb3@1.0.3
- snavbox@1.0.1
- skipthedishes_react@0.1.0
- sjs-lint-build1@1.0.4
- sjs-builder@1.0.5
- codyx-ai-windows-x64-baseline@1.14.42
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.