LWA-2026-5324 confirmed malware

transform-object-rest-spread@6.26.0

Malicious code in transform-object-rest-spread (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

transform-object-rest-spread@6.26.0 is a dependency-confusion / combosquat package published by an unrelated party (not the legitimate Babel maintainers). It declares a dependency on 'ui-styles-pkg' from an external HTTP URL (hxxp://package[.]storeartifacts[.]com/npm/transform-object-rest-spread) rather than the npm registry. The package itself contains only a trivial 'Hello, world!' script with no lifecycle hooks, but the non-registry dependency URL can serve arbitrary code when the dependency is resolved during installation — a weaponization vector for future updates to that URL.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 06:08 AM
analyzed
Jun 15, 2026, 06:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.