@grab-food/order-sdk-web@1.0.1
Malicious code in @grab-food/order-sdk-web (npm)
Analysis
Package @grab-food/order-sdk-web is an empty stub (module.exports = {} with echo-only lifecycle hooks) that declares a dependency fetched from a non-npm registry at registry[.]grivy-packages[.]com. The dependency tarball URL is hxxps://registry[.]grivy-packages[.]com/grab-food-order-sdk-web-core/-/grab-food-order-sdk-web-core-1[.]0[.]1[.]tgz. When installed, npm will download and execute code from this external, untrusted host. The package has no repository, no meaningful functionality, and its scoped name mimics the Grab food-delivery brand. The external registry host (grivy-packages[.]com) is the IOC for the second-stage payload delivery.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 09:05 AM
- analyzed
- Jul 8, 2026, 09:06 AM
Related advisories
- testudo-pack@1.0.0
- testis-pack@1.0.0
- n8n-nodes-mcputils@0.1.5
- tslint-conf@7.2.1
- ts-await@3.1.8
- url-func-registry@1.0.4
- @vite-ln/build-ts@5.17.0
- chain-async-dom@1.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.