LWA-2026-5954 MAL-2026-6422 ↗ confirmed malware

leo-config@1.1.1

Malicious code in leo-config (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or Information

Analysis

leo-config@1.1.1 is a trojanized clone of the legitimate leo-config library. Its main entry point (index.js) is a 5MB obfuscated blob containing only an eval of a number array with no exported functionality — the package does not implement the config library behaviour described in its README. It ships a binding.gyp file that executes index.js during npm install via 'node index.js > /dev/null 2>&1 && echo stub.c'. It also depends on 'bun' at version ^1.3.13 (not the legitimate Bun runtime), which is known from prior supply-chain attacks.

analyzed by
Leitwacht
first seen
Jun 24, 2026, 11:06 PM
analyzed
Jun 24, 2026, 11:10 PM
weekly installs
1,709

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.