LWA-2026-6961 confirmed malware
vaparklink@1.0.0
Malicious code in vaparklink (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package vaparklink@1.0.0 is a heavily obfuscated npm package that claims to auto-connect Discord bots to free Lavalink audio nodes. All source code is obfuscated using javascript-obfuscator, preventing static verification of its runtime behavior. The package has no lifecycle hooks and no observable token-theft or credential-exfiltration code in static analysis, but the obfuscation could conceal runtime-only malicious payloads. The package has no repository with verifiable content.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 06:36 PM
- analyzed
- Jul 20, 2026, 06:37 PM
Related advisories
- topk-js@0.12.0
- twilio-internal@99.99.99
- twilio-functions@99.99.99
- json-validator-utils@1.0.1
- relativity-pdfjs-dist@5.8.2
- @queenanya/baileys@9.7.1
- habingeer@2.1.6
- clover-codelab-remote-pay-cloud@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.