LWA-2026-5639 MAL-2026-6330 ↗ confirmed malware

@ravespaceio/rave-engine@99.0.1

Malicious code in @ravespaceio/rave-engine (npm)

Analysis

Dependency-confusion stub published with an inflated version number to outrank a private package of the same scoped name and win install resolution. The package.json preinstall lifecycle script executes curl against a hardcoded remote IP on port 1337, sending an install-time beacon before the package is ever used. index.js repeats the same outbound request via child_process execSync so it also fires when the module is required. The package ships no real functionality (empty exports); its only purpose is to phone home to attacker infrastructure when installed inside a targeted environment.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 10:57 AM
analyzed
Jun 17, 2026, 11:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.