LWA-2026-6268 MAL-2026-10136 ↗ confirmed malware

transform-es2015-sticky-regex@6.24.3

Malicious code in transform-es2015-sticky-regex (npm)

T1195.002 · Compromise Software Supply ChainT1192 · Dependency ConfusionT1105 · Ingress Tool Transfer

Analysis

A dependency hijack via a self-referencing external URL. The package transform-es2015-sticky-regex (combosquat of the Babel transform plugin naming) declares a dependency and devDependency on itself at the URL hxxp://pack[.]nppacks[.]com/npm/transform-es2015-sticky-regex — a plain-HTTP attacker-controlled endpoint. When npm resolves the dependency graph, it fetches and installs code from that server, enabling the attacker to deliver arbitrary payloads to every install target. The shipped index.js contains a benign Babel plugin (red herring); the actual malicious delivery channel is the external URL dependency resolution at install time.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 06:00 PM
analyzed
Jul 2, 2026, 06:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.