LWA-2026-5377 confirmed malware
uphold-sdk-javascript-extensions@99.9.10
Malicious code in uphold-sdk-javascript-extensions (npm)
T1195.002 · Compromise Software Supply ChainT1195.001 · Compromise Software Dependencies and Development Tools
Analysis
Package combosquats the legitimate Uphold financial SDK name with an inflated version number (99.9.10). It ships with an empty code file and no functionality. Both dependencies and devDependencies resolve the "base-package" dependency from the non-registry URL hxxp://npm[.]ezequielpuig[.]space/, an attacker-controlled server. When installed, npm resolves this dependency from the custom registry, enabling the attacker to serve arbitrary malicious code and payloads at install time.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 12:31 PM
- analyzed
- Jun 15, 2026, 12:32 PM
Related advisories
- ryan-pdf-js@99.9.1
- @paoletti/viem@2.53.1
- u-paging@0.0.0
- vitest-pro@7.0.4
- unico-check@9.9.9
- unicocheck-ios@9.9.9
- unico-android@9.9.9
- cardano-addresses-docs@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.