LWA-2026-5496 MAL-2026-5919 ↗ confirmed malware

pretie_x1@3.8.5

Malicious code in pretie_x1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package pretie_x1 impersonates the prettier code formatter. It fetches and executes a remote JavaScript payload from api[.]aavcareer[.]ink or deep-ai-guard[.]store at install time. The downloaded code can perform arbitrary operations on the victim system.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 02:55 AM
analyzed
Jun 16, 2026, 02:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.