LWA-2026-7155 confirmed malware

@sqlite-prime/createsql@1.0.0

Malicious code in @sqlite-prime/createsql (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

When imported, this package fetches JavaScript code from a GitHub Gist (getchainverse/198a0bbec7a6018e9250615d26e37b90) via the GitHub API and executes it with eval(). The Gist content is attacker-controlled, making this a remote-code-execution dropper. The package has no lifecycle hooks — the payload runs on require().

analyzed by
Leitwacht
first seen
Jul 27, 2026, 03:39 PM
analyzed
Jul 27, 2026, 03:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.