LWA-2026-5470 MAL-2026-4723 ↗ confirmed malware

weavedb-sdk@0.45.3

Malicious code in weavedb-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1204.002 · Malicious FileT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool Transfer

Analysis

Package weavedb-sdk@0.45.3 is a trojanized clone of the legitimate WeaveDB SDK. It ships a 976KB UPX-packed ELF binary at `./tools/setup` executed via the `preinstall` lifecycle hook. The binary is a Mini Shai-Hulud worm variant: upon install it harvests environment variables including NPM_TOKEN from the victim's system and uses them to self-propagate by republishing malicious versions to other packages the victim maintains. The binary communicated with Cloudflare-protected endpoints (104.16.x.x range) during execution. The package was officially deprecated by npm with the message 'COMPROMISED via Mini Shai-Hulud worm (TeamPCP).' The package also pulls in known compromised dependencies (weavedb-base, weavedb-contracts) as secondary payload delivery mechanisms.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 12:19 AM
analyzed
Jun 16, 2026, 12:21 AM
weekly installs
797

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.