transform-es2015-classes@6.25.1
Malicious code in transform-es2015-classes (npm)
Analysis
The package name transform-es2015-classes mimics the legitimate Babel plugin babel-plugin-transform-es2015-classes. It ships code that does not match its name (a constant-replacement plugin, not a class transformer). It declares a dependency "ts" from an HTTP URL (hxxp://npm[.]artifactsnpm[.]com/npm/transform-es2015-classes) — a non-HTTPS, non-registry host — allowing arbitrary code to be served at install time through dependency resolution. The package also lists several heavy unused dependencies (react, axios, ws, node-fetch) that are not imported in the shipped code. No repository URL is provided; the description is the generic single word "NPM".
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:52 AM
- analyzed
- Jun 15, 2026, 05:55 AM
Related advisories
- transform-es3-member-expression-literals@6.24.0
- toast-react-slider@1.0.0
- redirect-azlazy@1.0.0
- oit-lib-oracle-util@45.0.0
- no-date-parsing@2.2.0
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.