LWA-2026-5240 confirmed malware
swagger-express-validators@1.0.0
Malicious code in swagger-express-validators (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1195.002 · Compromise Software Supply Chain
Analysis
This package contains a remote code loader in its main entry point (index.js). When the exported function is called, it makes an HTTPS GET request to solidbitcapital[.]com/solidbitcapital[.]com with path /ft?id=ggTDkCbB%2Fr6oddsM34y45cvZ1xg86mB5UrLF3tQCjo8q8uPYHvmvqxxIS8wchXV1, using the system platform as the User-Agent header, and evaluates the response as JavaScript via eval(). This loads and executes arbitrary second-stage code from the remote server. The package name combosquats the legitimate swagger-express-validator naming pattern.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 11:48 AM
- analyzed
- Jun 14, 2026, 11:49 AM
Related advisories
- svg2text@3.0.0
- super-test-json@1.2.0
- st-pathhelper@1.0.0
- stacknova@1.0.0
- sqrt-bn-enhanced@2.0.9
- spectral-corsair@999.999.1000
- sort-btree@2.1.4
- solidity-compile-deploy@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.