@sqlite-tag/schema-generator@1.0.2
Malicious code in @sqlite-tag/schema-generator (npm)
T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information
Analysis
The package index.js fetches a remote payload from a GitHub Gist (gist[.]github[.]com/getchainverse/b57a92378ad0a52430137c3b810e7107.js) via the GitHub API and executes it with eval(), giving the attacker full control over what code runs in the installer's environment. The package has no lifecycle hooks — the fetch+eval runs on require(). The package description and repository URL are unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 09:47 AM
- analyzed
- Jul 15, 2026, 09:47 AM
Related advisories
- react-hook-doms@5.3.1
- assertion-utils-js@2.4.3
- @risaoffc/baileys@8.0.3
- ethers-core@6.13.7
- chai-as-sets@3.1.3
- chai-as-hardened@7.0.9
- @asyncapi/specs@6.11.2
- @asyncapi/generator-helpers@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.