LWA-2026-5467 MAL-2026-4715 ↗ confirmed malware

weavedb-base@0.45.3

Malicious code in weavedb-base (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1204.002 · Malicious File

Analysis

weavedb-base@0.45.3 is a trojanized version of the legitimate WeaveDB decentralized database SDK. The package contains a preinstall lifecycle script ("./vendor/setup") that executes a bundled native ELF binary (vendor/setup, ~976KB) at install time. The npm publisher account was compromised, and the legitimate publisher later deprecated this version with a warning that it was infected by the Mini Shai-Hulud worm. The runtime execution of the binary failed in sandbox analysis (exit code 127), but the preinstall hook is armed and would execute the binary on any system where it runs successfully.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 12:13 AM
analyzed
Jun 16, 2026, 12:15 AM
weekly installs
792

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.