LWA-2026-6046 MAL-2026-6418 ↗ confirmed malware

leo-aws@2.0.4

Malicious code in leo-aws (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

Package leo-aws@2.0.4 is a compromised version of the legitimate leo-aws AWS helper library. The main entry point (index.js, 5.2 MB) was replaced with an obfuscated script that attempts dynamic code execution via a Caesar-cipher-decoded eval on an array of character codes. The obfuscation errors out (the eval call throws a TypeError, caught by an empty try/catch), rendering the package non-functional — requiring it returns an empty module. The legitimate AWS wrapper code (factory.js, lib/*) remains present in the tarball but is unreachable. The artifact is a trojanized clone resulting from an account takeover of the original publisher.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 06:24 AM
analyzed
Jun 27, 2026, 09:24 PM
weekly installs
1,730

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.