LWA-2026-6248 MAL-2026-10533 ↗ confirmed malware

lusha-iam-widgets@1.5.2

Malicious code in lusha-iam-widgets (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

The package pins its node-fetch dependency to a full URL pointing at an attacker-controlled custom registry (registry[.]ctzbg[.]com) instead of a standard npm semver range. When npm installs this package, it fetches node-fetch from that external registry, which the attacker controls and can serve arbitrary code as that dependency at any time. The package ships benign-looking React UI components (styled-components, MultipleInvites) as camouflage; the attack vector is the dependency resolution itself. IOC: registry[.]ctzbg[.]com.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 01:28 PM
analyzed
Jul 2, 2026, 01:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.