LWA-2026-5523 MAL-2026-5267 ↗ confirmed malware

wrangler-deploy@1.5.5

Malicious code in wrangler-deploy (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

wrangler-deploy@1.5.5 is a trojanized version of the Cloudflare Workers deployment tool. The main entry point (index.js) contains an obfuscated eval decoder that attempts to dynamically construct and execute code via a Caesar-cipher rotation of hardcoded char-code arrays. The injection is placed at the top of the bundled package entry, outside the normal library code. The publisher has deprecated this version with a public advisory stating it is a compromised supply-chain build linked to a worm campaign. Users should immediately upgrade to a known-good release and investigate any CI/CD pipelines that may have installed this version for potential credential exposure.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 06:13 AM
analyzed
Jun 16, 2026, 06:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.