LWA-2026-6471 MAL-2026-10103 ↗ confirmed malware

optimize-regex@1.2.1

Malicious code in optimize-regex (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package optimize-regex@1.2.1 declares a self-referencing dependency via an external HTTP URL (hxxp://pack[.]nppacks[.]com/npm/optimize-regex) in both dependencies and devDependencies. The host pack[.]nppacks[.]com is a non-registry, non-standard server controlled by the attacker. When npm resolves this dependency, arbitrary code can be served from that URL and installed into the dependency tree. The shipped index.js is a decoy Babel plugin with no malicious runtime behavior; the attack vector is the external dependency declaration itself.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 07:23 PM
analyzed
Jul 8, 2026, 07:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.