LWA-2026-5242 confirmed malware

sycm-vendors@55.0.0

Malicious code in sycm-vendors (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package sycm-vendors@55.0.0 is a supply-chain attack that hijacks npm install resolution via a malicious dependency entry. Its package.json declares a self-referencing dependency with a tarball URL pointing to an attacker-controlled server at hxxps://repo[.]securityctrl[.]com/sycm-vendors. When npm resolves this dependency during install, it fetches a malicious tarball from that external host. The package's own shipped code is a 92-byte stub that prints a benign message; the README claims to be a "placeholder" — both are camouflage. The actual payload is delivered from the external URL at install time.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 12:19 PM
analyzed
Jun 14, 2026, 12:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.