pretie_x2@3.8.5
Malicious code in pretie_x2 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1564.003 · Hidden Window
Analysis
pretie_x2@3.8.5 installs and executes code that fetches a remote JavaScript file from api[.]aavcarer[.]ink and runs it as a hidden Node subprocess. It spoofs the name of the prettier code formatter.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 03:02 AM
- analyzed
- Jun 16, 2026, 03:07 AM
Related advisories
- bubblestr@1.1.4
- texttweak-kit@1.0.0
- textify-kit@1.0.0
- strutil-kit@1.0.0
- str-master@1.0.11
- strmagic-kit@1.0.0
- string-utils-kit@1.0.0
- stringsculpt-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.