LWA-2026-6232 MAL-2026-10200 ↗ confirmed malware

api-changelly@19.2.11

Malicious code in api-changelly (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

Combosquat package mimicking the Changelly cryptocurrency exchange API. Installs a preinstall lifecycle hook that executes arbitrary JavaScript code (node index.js) on npm install, before the intended package is installed. The tarball was removed from the registry shortly after publication, consistent with a publish-and-burn pattern. No repository, description, or author is declared. The package has no legitimate functionality.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 10:40 AM
analyzed
Jul 2, 2026, 08:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.