api-changelly@19.2.11
Malicious code in api-changelly (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
Combosquat package mimicking the Changelly cryptocurrency exchange API. Installs a preinstall lifecycle hook that executes arbitrary JavaScript code (node index.js) on npm install, before the intended package is installed. The tarball was removed from the registry shortly after publication, consistent with a publish-and-burn pattern. No repository, description, or author is declared. The package has no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 10:40 AM
- analyzed
- Jul 2, 2026, 08:43 AM
Related advisories
- @marketfront/actualordersnippetpopup@7.0.0
- @marketfront/basemarkettemplate@7.0.0
- @marketfront/advertisingdevtool@7.0.0
- svgson-lite@1.0.4
- svgcraft-core@1.0.1
- notify-theme@1.3.5
- chain-chai-async@1.3.5
- date-fns-lite@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.