leo-aws@2.0.4
Malicious code in leo-aws (npm)
Analysis
Package leo-aws@2.0.4 is a compromised version of the legitimate leo-aws AWS helper library. The main entry point (index.js, 5.2 MB) was replaced with an obfuscated script that attempts dynamic code execution via a Caesar-cipher-decoded eval on an array of character codes. The obfuscation errors out (the eval call throws a TypeError, caught by an empty try/catch), rendering the package non-functional — requiring it returns an empty module. The legitimate AWS wrapper code (factory.js, lib/*) remains present in the tarball but is unreachable. The artifact is a trojanized clone resulting from an account takeover of the original publisher.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 06:24 AM
- analyzed
- Jun 27, 2026, 09:24 PM
- weekly installs
- 1,730
Related advisories
- chai-as-assured@7.1.2
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@3.0.2
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
- txs-builder@1.0.6
- hexo-shoka-swiper@0.1.10
- hexo-deployer-wrangler@1.0.4
- leo-config@1.1.1
- zenith-utils@12.0.14
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.