LWA-2026-5514 confirmed malware

wm-idp-sdk@1.2.0

Malicious code in wm-idp-sdk (npm)

T1195 · Supply Chain CompromiseT1195.002 · Compromise Software Supply Chain

Analysis

wm-idp-sdk@1.2.0 declares a dependency on the legitimate `ky` HTTP client package but pins it to `hxxps://registry[.]ctzbg[.]com/wm-idp-sdk/ky` — a non-standard, attacker-controlled registry instead of the official npm registry. When installed, npm resolves `ky` from ctzbg[.]com, which can serve arbitrary malicious code. The package's own bundled `dist/main.js` never actually imports `ky` — the dependency is declared solely as a delivery vector. The publisher email is obfuscated and this is the only published version.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 04:43 AM
analyzed
Jun 16, 2026, 04:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.