weavedb-node-client@0.45.3
Malicious code in weavedb-node-client (npm)
Analysis
weavedb-node-client@0.45.3 is a trojanized clone of the legitimate WeaveDB gRPC client. It ships a 977KB ELF binary at tools/setup that executes during npm install via the preinstall lifecycle hook. This binary is the Mini Shai-Hulud worm (TeamPCP campaign) — a native dropper that downloads second-stage payloads and harvests NPM tokens and other credentials from the victim environment. The package also depends on weavedb-base (another compromised component in the same worm campaign). The preinstall hook runs: ./tools/setup. The legitimate index.js and weavedb.proto files serve as camouflage for the malicious binary payload.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 12:16 AM
- analyzed
- Jun 16, 2026, 12:18 AM
- weekly installs
- 368
Related advisories
- vl-ui-code-preview@10.1.1
- vl-ui-body@10.1.1
- vl-ui-breadcrumb@10.1.1
- vl-ui-checkbox@10.1.1
- vl-ui-alert@99.99.2
- vl-ui-accessibility@99.99.1
- unico-check@9.9.9
- unico-android@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.