weavedb-client@0.45.3
Malicious code in weavedb-client (npm)
Analysis
weavedb-client@0.45.3 is a trojanized version of the WeaveDB client SDK, compromised as part of the Mini Shai-Hulud supply-chain worm campaign. The package executes a bundled 976KB ELF binary (scripts/postbuild) during the preinstall lifecycle hook — no legitimate build step is performed. The payload is a multi-stage worm that harvests NPM tokens from the installer's environment and propagates by publishing malicious packages to accounts the victim has access to. The package also depends on weavedb-base (its sibling compromised package in the same campaign). Indicators: preinstall hook at ./scripts/postbuild; a 976KB ELF binary at scripts/postbuild; the package ships a full yarn-error.log from the attacker's build machine revealing propagation to the typosquat target 'weavedb-bse'.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 12:14 AM
- analyzed
- Jun 16, 2026, 12:17 AM
- weekly installs
- 895
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.