LWA-2026-6671 confirmed malware

finvu-hdfc-sdk@99.9.9

Malicious code in finvu-hdfc-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Combosquat package impersonating the finvu HDFC financial SDK. The package is a 38-byte stub with no meaningful code — its only purpose is to declare an external tarball dependency at hxxps://storage[.]googleapis[.]com/lscunpentest/pack_ux_foundry[.]tgz. When npm install resolves this dependency, it fetches and extracts the attacker-controlled tarball from the GCS bucket, delivering whatever payload the attacker chooses. The package has no repository, no README, and no lifecycle hooks — the entire attack is the off-registry dependency pulling untrusted code at install time.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 11:47 AM
analyzed
Jul 13, 2026, 11:48 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.