@sqlite-panel/createsql@1.0.0
Malicious code in @sqlite-panel/createsql (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
@sqlite-panel/createsql@1.0.0 is a combosquat package that acts as a remote code execution dropper. On require(), it fetches a JavaScript payload from a GitHub gist (api[.]github[.]com/gists/198a0bbec7a6018e9250615d26e37b90) and executes it via eval(). The gist is hosted under the publisher's own GitHub account, giving them full control over the delivered payload at runtime. The package has no repository, no description, and no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 09:51 PM
- analyzed
- Jul 13, 2026, 09:57 PM
Related advisories
- type-unique@3.1.3
- type-swap@3.1.3
- monitoring-service-util@1.0.0
- type-astr@3.2.3
- chai-as-verified@7.1.5
- polymarket-stake-kelly-math-check@3.5.2
- route-processor@3.1.5
- font-huge@2.5.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.