LWA-2026-6470 confirmed malware

no-for-of-loops@1.0.1

Malicious code in no-for-of-loops (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package declares a self-referencing dependency via an attacker-controlled HTTP URL (hxxp://pack[.]nppacks[.]com/npm/no-for-of-loops) in both dependencies and devDependencies. On npm install, the package manager fetches the tarball from this non-registry host, allowing the attacker to serve arbitrary malicious code at install time. The HTTP protocol also enables man-in-the-middle tampering. The package's own source code is a benign Babel plugin for compile-time constant replacement, but the manifest hijacks dependency resolution to an external attacker-controlled endpoint.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 07:01 PM
analyzed
Jul 8, 2026, 07:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.