pretie_x1@3.8.5
Malicious code in pretie_x1 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Package pretie_x1 impersonates the prettier code formatter. It fetches and executes a remote JavaScript payload from api[.]aavcareer[.]ink or deep-ai-guard[.]store at install time. The downloaded code can perform arbitrary operations on the victim system.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 02:55 AM
- analyzed
- Jun 16, 2026, 02:57 AM
Related advisories
- web-pool@2.3.5
- wordpad-text-ui@1.0.0
- webpack-cdn-fetcher@1.0.1
- weavedb-node-client@0.45.3
- vui-gateway@45.0.0
- vue-template-compiler-plugin@2.7.16
- vourfly-tele@4.7.6
- vite-enhancer-config@1.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.