LWA-2026-6163 confirmed malware

lil-swisgom-hlepers@1.0.0

Malicious code in lil-swisgom-hlepers (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package lil-swisgom-hlepers@1.0.0 is a stub that declares a dependency on lil-swisgom-hlepers-core resolved from the external host hxxps://registry[.]grivy-packages[.]com/lil-swisgom-hlepers-core/-/lil-swisgom-hlepers-core-1[.]0[.]0[.]tgz instead of the public npm registry. This causes npm to fetch and execute code from an attacker-controlled server during installation, bypassing standard dependency resolution. The published tarball itself is empty (module.exports = {} with echo-only install hooks), making the package appear benign while the real payload is served remotely from registry[.]grivy-packages[.]com.

analyzed by
Leitwacht
first seen
Jun 29, 2026, 09:25 PM
analyzed
Jun 29, 2026, 09:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.