LWA-2026-6709 MAL-2026-10460 ↗ confirmed malware

datavaultx@1.7.1

Malicious code in datavaultx (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

Package datavaultx@1.7.1 is a trojanized clone of the pino logger, published under a misleading name suggesting an authentication/vault module. The main entry point (auth.js) requires lib/writer.js, which attempts to load the package auth-gen-next. If that package is not already installed, writer.js runs `npm install auth-gen-next --no-warnings --no-save --no-progress --loglevel silent` via execSync to download and install it, then requires it. This results in remote code execution of the downloaded package on the installer's system at the moment the module is loaded.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 02:40 PM
analyzed
Jul 13, 2026, 02:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.