LWA-2026-5180 confirmed malware

sort-destructure-keys@7.9.0

Malicious code in sort-destructure-keys (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

The package ships only a minimal stub (index.js logs 'Hello, world!') but declares a dependency 'ui-styles-pkg' that resolves from an external non-npm HTTP registry at hxxp://npm[.]jpartifacts[.]com/npm/sort-destructure-keys. This URL appears in both dependencies and devDependencies in package.json. When the package is installed, npm resolves 'ui-styles-pkg' from this attacker-controlled host, which can serve arbitrary code at install time — an artifact-poisoning / dependency-confusion vector. The C2 registry host is npm[.]jpartifacts[.]com (HTTP, port 80).

analyzed by
Leitwacht
first seen
Jun 14, 2026, 04:04 AM
analyzed
Jun 14, 2026, 04:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.