wrangler-deploy@1.5.5
Malicious code in wrangler-deploy (npm)
Analysis
wrangler-deploy@1.5.5 is a trojanized version of the Cloudflare Workers deployment tool. The main entry point (index.js) contains an obfuscated eval decoder that attempts to dynamically construct and execute code via a Caesar-cipher rotation of hardcoded char-code arrays. The injection is placed at the top of the bundled package entry, outside the normal library code. The publisher has deprecated this version with a public advisory stating it is a compromised supply-chain build linked to a worm campaign. Users should immediately upgrade to a known-good release and investigate any CI/CD pipelines that may have installed this version for potential credential exposure.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 06:13 AM
- analyzed
- Jun 16, 2026, 06:16 AM
Related advisories
- wp-boilerplate@1.0.1
- work-planner-client@1.0.0
- chai-solidity-testkit@1.6.1
- workbox-stable-xyz@1.0.0
- wordsmith-kit@1.0.0
- wm-idp-sdk@1.2.0
- wisdomtreetest@1.0.1
- winutils-fetch@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.