LWA-2026-6453 confirmed malware

@grab-food/order-sdk-web@1.0.1

Malicious code in @grab-food/order-sdk-web (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package @grab-food/order-sdk-web is an empty stub (module.exports = {} with echo-only lifecycle hooks) that declares a dependency fetched from a non-npm registry at registry[.]grivy-packages[.]com. The dependency tarball URL is hxxps://registry[.]grivy-packages[.]com/grab-food-order-sdk-web-core/-/grab-food-order-sdk-web-core-1[.]0[.]1[.]tgz. When installed, npm will download and execute code from this external, untrusted host. The package has no repository, no meaningful functionality, and its scoped name mimics the Grab food-delivery brand. The external registry host (grivy-packages[.]com) is the IOC for the second-stage payload delivery.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 09:05 AM
analyzed
Jul 8, 2026, 09:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.