LWA-2026-5315 confirmed malware
transform-es3-member-expression-literals@6.24.0
Malicious code in transform-es3-member-expression-literals (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
Combosquat of the Babel plugin babel-plugin-transform-es3-member-expression-literals. The package declares a self-dependency to hxxp://pack[.]nppacks[.]com/npm/transform-es3-member-expression-literals — an attacker-controlled HTTP host — in both dependencies and devDependencies, so npm resolves code from that external server on install. The published index.js is a minimal stub containing only "console.log('Hello, world!')", while the actual payload is served from the external dependency URL at pack[.]nppacks[.]com.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:52 AM
- analyzed
- Jun 15, 2026, 05:54 AM
Related advisories
- toast-react-slider@1.0.0
- redirect-azlazy@1.0.0
- oit-lib-oracle-util@45.0.0
- no-date-parsing@2.2.0
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.