LWA-2026-6343 MAL-2026-6916 ↗ confirmed malware

@sqlite-list/schema-generator@1.0.2

Malicious code in @sqlite-list/schema-generator (npm)

T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information

Analysis

The package index.js fetches a remote script from a GitHub gist (getchainverse/198a0bbec7a6018e9250615d26e37b90 or getchainverse/b57a92378ad0a52430137c3b810e7107) via the GitHub API and executes it with eval(). The gist content is attacker-controlled and can be changed at any time, making this a remote-code-execution dropper. The package has no repository, no description, and no lifecycle hooks — the payload runs when the module is required.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 09:07 PM
analyzed
Jul 5, 2026, 09:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.