lusha-iam-widgets@1.5.2
Malicious code in lusha-iam-widgets (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
The package pins its node-fetch dependency to a full URL pointing at an attacker-controlled custom registry (registry[.]ctzbg[.]com) instead of a standard npm semver range. When npm installs this package, it fetches node-fetch from that external registry, which the attacker controls and can serve arbitrary code as that dependency at any time. The package ships benign-looking React UI components (styled-components, MultipleInvites) as camouflage; the attack vector is the dependency resolution itself. IOC: registry[.]ctzbg[.]com.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 01:28 PM
- analyzed
- Jul 2, 2026, 01:29 PM
Related advisories
- driftpin@1.0.0
- ryan-pdf-js@99.9.1
- chai-as-assured@7.1.2
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
- wac-atl-context@99.9.1
- transform-es2015-classes@6.25.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.