LWA-2026-5323 confirmed malware
transform-object-assign@6.22.0
Malicious code in transform-object-assign (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
Package transform-object-assign@6.22.0 resolves its dependency "ui-styles-pkg" over plain HTTP from hxxp://package[.]storeartifacts[.]com/npm/transform-object-assign — a non-standard, non-npm host with no TLS and no integrity verification. Any code fetched from that URL executes as part of the install dependency chain, giving the external server full control over the dependency's behaviour when the package is required.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 06:08 AM
- analyzed
- Jun 15, 2026, 06:10 AM
Related advisories
- tracing-str@1.0.0
- transform-es2015-classes@6.25.1
- transform-es3-member-expression-literals@6.24.0
- transform-es2015-destructuring@6.24.1
- transform-es2015-typeof-symbol@6.24.1
- tradepilot@2.3.3
- tracking-service-config@90.0.0
- totally-legit-web-pack@1.2.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.