LWA-2026-6233 MAL-2026-6770 ↗ confirmed malware

@marketfront/changefilter@7.0.0

Malicious code in @marketfront/changefilter (npm)

Analysis

On install, the postinstall hook (scripts/postinstall.js) executes a 164KB javascript-obfuscator-obfuscated payload. The package poses as an internal configuration loader but is published publicly on npm. The postinstall script sends telemetry to telemetry[.]marketfront[.]io and executes obfuscated code. The package has no repository, no prior versions, and uses a fake internal infrastructure domain (github[.]marketfront[.]io). The same publisher simultaneously published @marketfront/actualordersnippetpopup@7.0.0 with an identical obfuscated postinstall payload, which has been independently confirmed as malware.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 08:43 AM
analyzed
Jul 2, 2026, 08:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.