LWA-2026-5377 confirmed malware

uphold-sdk-javascript-extensions@99.9.10

Malicious code in uphold-sdk-javascript-extensions (npm)

T1195.002 · Compromise Software Supply ChainT1195.001 · Compromise Software Dependencies and Development Tools

Analysis

Package combosquats the legitimate Uphold financial SDK name with an inflated version number (99.9.10). It ships with an empty code file and no functionality. Both dependencies and devDependencies resolve the "base-package" dependency from the non-registry URL hxxp://npm[.]ezequielpuig[.]space/, an attacker-controlled server. When installed, npm resolves this dependency from the custom registry, enabling the attacker to serve arbitrary malicious code and payloads at install time.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 12:31 PM
analyzed
Jun 15, 2026, 12:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.