LWA-2026-5468 MAL-2026-4716 ↗ confirmed malware

weavedb-client@0.45.3

Malicious code in weavedb-client (npm)

Analysis

weavedb-client@0.45.3 is a trojanized version of the WeaveDB client SDK, compromised as part of the Mini Shai-Hulud supply-chain worm campaign. The package executes a bundled 976KB ELF binary (scripts/postbuild) during the preinstall lifecycle hook — no legitimate build step is performed. The payload is a multi-stage worm that harvests NPM tokens from the installer's environment and propagates by publishing malicious packages to accounts the victim has access to. The package also depends on weavedb-base (its sibling compromised package in the same campaign). Indicators: preinstall hook at ./scripts/postbuild; a 976KB ELF binary at scripts/postbuild; the package ships a full yarn-error.log from the attacker's build machine revealing propagation to the typosquat target 'weavedb-bse'.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 12:14 AM
analyzed
Jun 16, 2026, 12:17 AM
weekly installs
895

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.