LWA-2026-6728 MAL-2026-10490 ↗ confirmed malware

@sqlite-panel/createsql@1.0.0

Malicious code in @sqlite-panel/createsql (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

@sqlite-panel/createsql@1.0.0 is a combosquat package that acts as a remote code execution dropper. On require(), it fetches a JavaScript payload from a GitHub gist (api[.]github[.]com/gists/198a0bbec7a6018e9250615d26e37b90) and executes it via eval(). The gist is hosted under the publisher's own GitHub account, giving them full control over the delivered payload at runtime. The package has no repository, no description, and no legitimate functionality.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 09:51 PM
analyzed
Jul 13, 2026, 09:57 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.