LWA-2026-5323 confirmed malware

transform-object-assign@6.22.0

Malicious code in transform-object-assign (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

Package transform-object-assign@6.22.0 resolves its dependency "ui-styles-pkg" over plain HTTP from hxxp://package[.]storeartifacts[.]com/npm/transform-object-assign — a non-standard, non-npm host with no TLS and no integrity verification. Any code fetched from that URL executes as part of the install dependency chain, giving the external server full control over the dependency's behaviour when the package is required.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 06:08 AM
analyzed
Jun 15, 2026, 06:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.