LWA-2026-5312 confirmed malware

transform-es2015-classes@6.25.1

Malicious code in transform-es2015-classes (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

The package name transform-es2015-classes mimics the legitimate Babel plugin babel-plugin-transform-es2015-classes. It ships code that does not match its name (a constant-replacement plugin, not a class transformer). It declares a dependency "ts" from an HTTP URL (hxxp://npm[.]artifactsnpm[.]com/npm/transform-es2015-classes) — a non-HTTPS, non-registry host — allowing arbitrary code to be served at install time through dependency resolution. The package also lists several heavy unused dependencies (react, axios, ws, node-fetch) that are not imported in the shipped code. No repository URL is provided; the description is the generic single word "NPM".

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:52 AM
analyzed
Jun 15, 2026, 05:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.