sycm-vendors@55.0.0
Malicious code in sycm-vendors (npm)
Analysis
Package sycm-vendors@55.0.0 is a supply-chain attack that hijacks npm install resolution via a malicious dependency entry. Its package.json declares a self-referencing dependency with a tarball URL pointing to an attacker-controlled server at hxxps://repo[.]securityctrl[.]com/sycm-vendors. When npm resolves this dependency during install, it fetches a malicious tarball from that external host. The package's own shipped code is a 92-byte stub that prints a benign message; the README claims to be a "placeholder" — both are camouflage. The actual payload is delivered from the external URL at install time.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 12:19 PM
- analyzed
- Jun 14, 2026, 12:20 PM
Related advisories
- swplayer-react-sl@1.0.5
- super-useful-omega-package-123@0.2.1
- strutil-kit@1.0.0
- streamvault@1.0.1
- st-pathhelper@1.0.0
- stacknova@1.0.0
- sort-btree@2.1.4
- solana-token-api@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.