no-for-of-loops@1.0.1
Malicious code in no-for-of-loops (npm)
Analysis
Package declares a self-referencing dependency via an attacker-controlled HTTP URL (hxxp://pack[.]nppacks[.]com/npm/no-for-of-loops) in both dependencies and devDependencies. On npm install, the package manager fetches the tarball from this non-registry host, allowing the attacker to serve arbitrary malicious code at install time. The HTTP protocol also enables man-in-the-middle tampering. The package's own source code is a benign Babel plugin for compile-time constant replacement, but the manifest hijacks dependency resolution to an external attacker-controlled endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 07:01 PM
- analyzed
- Jul 8, 2026, 07:02 PM
Related advisories
- express-route-engine@3.6.6
- mchain-sdk@4.2.5
- @grab-food/order-sdk-web@1.0.1
- testudo-pack@1.0.0
- testis-pack@1.0.0
- n8n-nodes-mcputils@0.1.5
- tslint-conf@7.2.1
- ts-await@3.1.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.