optimize-regex@1.2.1
Malicious code in optimize-regex (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package optimize-regex@1.2.1 declares a self-referencing dependency via an external HTTP URL (hxxp://pack[.]nppacks[.]com/npm/optimize-regex) in both dependencies and devDependencies. The host pack[.]nppacks[.]com is a non-registry, non-standard server controlled by the attacker. When npm resolves this dependency, arbitrary code can be served from that URL and installed into the dependency tree. The shipped index.js is a decoy Babel plugin with no malicious runtime behavior; the attack vector is the external dependency declaration itself.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 07:23 PM
- analyzed
- Jul 8, 2026, 07:24 PM
Related advisories
- no-for-of-loops@1.0.1
- express-route-engine@3.6.6
- po-ops-local-dev@99.9.1
- chain-api-sdk@0.2.10
- cdc-market@99.9.9
- playerdata-core@9.9.1
- @vwfs-its/sf-sac-frontend@20.1.1
- dependency_confusions@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.