weavedb-node-client@0.45.3
Malicious code in weavedb-node-client (npm)
Analysis
weavedb-node-client@0.45.3 is a trojanized clone of the legitimate WeaveDB gRPC client. It ships a 977KB ELF binary at tools/setup that executes during npm install via the preinstall lifecycle hook. This binary is the Mini Shai-Hulud worm (TeamPCP campaign) — a native dropper that downloads second-stage payloads and harvests NPM tokens and other credentials from the victim environment. The package also depends on weavedb-base (another compromised component in the same worm campaign). The preinstall hook runs: ./tools/setup. The legitimate index.js and weavedb.proto files serve as camouflage for the malicious binary payload.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 12:16 AM
- analyzed
- Jun 16, 2026, 12:18 AM
- weekly installs
- 368
Related advisories
- weavedb-base@0.45.3
- @httpactions/encode-url@1.0.0
- ui-core-system@1.0.3
- toast-react-slider@1.0.0
- stylelint-standard@1.2.0
- strutil-kit@1.0.0
- str-master@1.0.11
- strmagic-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.