LWA-2026-6614 confirmed malware
cobo-ui-toolkit@1.0.5
Malicious code in cobo-ui-toolkit (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package declares a self-dependency resolved from an attacker-controlled HTTP server (hxxp://pack[.]nppacks[.]com/npm/cobo-ui-toolkit) instead of the npm registry. When installed, npm fetches the dependency from this external URL, allowing the attacker to serve arbitrary code at install time. The shipped index.js is a verbatim copy of the legitimate babel-plugin-transform-define library, serving as camouflage. The package name combosquats Cobo, a cryptocurrency custody platform, targeting crypto developers.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 09:33 AM
- analyzed
- Jul 11, 2026, 09:34 AM
Related advisories
- polymarket-kelly-math-stake@3.6.2
- supertokens-web@1.16.0
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- eth-react-redirection@1.0.0
- note-utilities@2.1.2
- chain-await-dom@1.3.4
- theta-sdk-js@1.2.14
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.