LWA-2026-5469 MAL-2026-4721 ↗ confirmed malware

weavedb-node-client@0.45.3

Malicious code in weavedb-node-client (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1204.002 · Malicious FileT1105 · Ingress Tool Transfer

Analysis

weavedb-node-client@0.45.3 is a trojanized clone of the legitimate WeaveDB gRPC client. It ships a 977KB ELF binary at tools/setup that executes during npm install via the preinstall lifecycle hook. This binary is the Mini Shai-Hulud worm (TeamPCP campaign) — a native dropper that downloads second-stage payloads and harvests NPM tokens and other credentials from the victim environment. The package also depends on weavedb-base (another compromised component in the same worm campaign). The preinstall hook runs: ./tools/setup. The legitimate index.js and weavedb.proto files serve as camouflage for the malicious binary payload.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 12:16 AM
analyzed
Jun 16, 2026, 12:18 AM
weekly installs
368

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.