lil-swisgom-hlepers@1.0.0
Malicious code in lil-swisgom-hlepers (npm)
Analysis
Package lil-swisgom-hlepers@1.0.0 is a stub that declares a dependency on lil-swisgom-hlepers-core resolved from the external host hxxps://registry[.]grivy-packages[.]com/lil-swisgom-hlepers-core/-/lil-swisgom-hlepers-core-1[.]0[.]0[.]tgz instead of the public npm registry. This causes npm to fetch and execute code from an attacker-controlled server during installation, bypassing standard dependency resolution. The published tarball itself is empty (module.exports = {} with echo-only install hooks), making the package appear benign while the real payload is served remotely from registry[.]grivy-packages[.]com.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 09:25 PM
- analyzed
- Jun 29, 2026, 09:26 PM
Related advisories
- chai-promised-test@1.3.5
- hardhat-compile-ethers@0.0.1
- jwtmethod@1.1.10
- clob-client-math@1.0.1
- hardhat-plugin-solidity@2.3.1
- authsessionbridge@1.6.29
- zyncmap@0.0.0
- ts-lint-builders-v2.1@2.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.