finvu-hdfc-sdk@99.9.9
Malicious code in finvu-hdfc-sdk (npm)
Analysis
Combosquat package impersonating the finvu HDFC financial SDK. The package is a 38-byte stub with no meaningful code — its only purpose is to declare an external tarball dependency at hxxps://storage[.]googleapis[.]com/lscunpentest/pack_ux_foundry[.]tgz. When npm install resolves this dependency, it fetches and extracts the attacker-controlled tarball from the GCS bucket, delivering whatever payload the attacker chooses. The package has no repository, no README, and no lifecycle hooks — the entire attack is the off-registry dependency pulling untrusted code at install time.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 11:47 AM
- analyzed
- Jul 13, 2026, 11:48 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.