leo-config@1.1.1
Malicious code in leo-config (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or Information
Analysis
leo-config@1.1.1 is a trojanized clone of the legitimate leo-config library. Its main entry point (index.js) is a 5MB obfuscated blob containing only an eval of a number array with no exported functionality — the package does not implement the config library behaviour described in its README. It ships a binding.gyp file that executes index.js during npm install via 'node index.js > /dev/null 2>&1 && echo stub.c'. It also depends on 'bun' at version ^1.3.13 (not the legitimate Bun runtime), which is known from prior supply-chain attacks.
- analyzed by
- Leitwacht
- first seen
- Jun 24, 2026, 11:06 PM
- analyzed
- Jun 24, 2026, 11:10 PM
- weekly installs
- 1,709
Related advisories
- zenith-utils@12.0.14
- theme-color-picker@2.0.28
- pino-zod@1.0.121
- tailwindcss-effector@1.7.0
- assertcore@3.1.7
- chalk-ultra@12.0.3
- node-fetch-utils@1.2.1
- aikaf668897@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.