LWA-2026-5315 confirmed malware

transform-es3-member-expression-literals@6.24.0

Malicious code in transform-es3-member-expression-literals (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Combosquat of the Babel plugin babel-plugin-transform-es3-member-expression-literals. The package declares a self-dependency to hxxp://pack[.]nppacks[.]com/npm/transform-es3-member-expression-literals — an attacker-controlled HTTP host — in both dependencies and devDependencies, so npm resolves code from that external server on install. The published index.js is a minimal stub containing only "console.log('Hello, world!')", while the actual payload is served from the external dependency URL at pack[.]nppacks[.]com.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:52 AM
analyzed
Jun 15, 2026, 05:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.