LWA-2026-6714 MAL-2026-10448 ↗ confirmed malware

@sqlite-group/schema-generator@1.0.2

Malicious code in @sqlite-group/schema-generator (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

@sqlite-group/schema-generator@1.0.2 is a combosquat package that acts as a remote-code-execution dropper. When imported (require), index.js fetches a GitHub Gist (b57a92378ad0a52430137c3b810e7107) via api[.]github[.]com and executes the gist content with eval(). The gist is controlled by the same publisher (getchainverse[.]com domain), allowing the attacker to serve arbitrary malicious code at any time. The package has no lifecycle hooks and no legitimate SQL functionality despite its name and description.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 04:02 PM
analyzed
Jul 13, 2026, 04:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.