LWA-2026-5313 confirmed malware
transform-es2015-destructuring@6.24.1
Malicious code in transform-es2015-destructuring (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071 · Application Layer Protocol
Analysis
Package combosquats a real Babel plugin. The package's manifest declares a self-dependency resolved from an external HTTP server (pack[.]nppacks[.]com) instead of the npm registry. When npm installs this package, it fetches and executes code from the attacker-controlled host, which can serve arbitrary malicious payloads with install-time lifecycle hooks. The package's own code is a 106-byte decoy that prints "Hello, world!" and has no real functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:52 AM
- analyzed
- Jun 15, 2026, 05:54 AM
Related advisories
- period-newline@0.1.0
- nodecheck-health@1.0.0
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.