LWA-2026-5313 confirmed malware

transform-es2015-destructuring@6.24.1

Malicious code in transform-es2015-destructuring (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071 · Application Layer Protocol

Analysis

Package combosquats a real Babel plugin. The package's manifest declares a self-dependency resolved from an external HTTP server (pack[.]nppacks[.]com) instead of the npm registry. When npm installs this package, it fetches and executes code from the attacker-controlled host, which can serve arbitrary malicious payloads with install-time lifecycle hooks. The package's own code is a 106-byte decoy that prints "Hello, world!" and has no real functionality.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:52 AM
analyzed
Jun 15, 2026, 05:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.