LWA-2026-5241 MAL-2026-2906 ↗ confirmed malware

swplayer-react-sl@1.0.5

Malicious code in swplayer-react-sl (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package scripts/install.js postinstall hook executes two fetch+eval chains: it base64-decodes and fetches remote JavaScript from hxxps://coingecko-liard[.]vercel[.]app/api/content and hxxps://coingecko-liard[.]vercel[.]app/api/old, then evaluates the response with eval(), executing arbitrary attacker-controlled code in the installer's context. At runtime the package attempted DNS resolution and HTTPS GET requests to these endpoints. The package masquerades as a React video player wrapper to deceive developers into installing it.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 12:18 PM
analyzed
Jun 14, 2026, 12:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.