weavedb-base@0.45.3
Malicious code in weavedb-base (npm)
Analysis
weavedb-base@0.45.3 is a trojanized version of the legitimate WeaveDB decentralized database SDK. The package contains a preinstall lifecycle script ("./vendor/setup") that executes a bundled native ELF binary (vendor/setup, ~976KB) at install time. The npm publisher account was compromised, and the legitimate publisher later deprecated this version with a warning that it was infected by the Mini Shai-Hulud worm. The runtime execution of the binary failed in sandbox analysis (exit code 127), but the preinstall hook is armed and would execute the binary on any system where it runs successfully.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 12:13 AM
- analyzed
- Jun 16, 2026, 12:15 AM
- weekly installs
- 792
Related advisories
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
- dtxto1ols@1.0.2
- dttfdsdee@1.0.1
- dddooo@1.0.0
- easy-string-kit232@1.0.8
- react-campaign-optimizer@1.0.0
- hyperpure-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.