LWA-2026-7156 confirmed malware

@sqlite-table/schema-generator@1.0.2

Malicious code in @sqlite-table/schema-generator (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

On require(), index.js fetches a remote payload from hxxps://api[.]github[.]com/gists/b57a92378ad0a52430137c3b810e7107 (a GitHub gist under the account "getchainverse") and executes it via eval(). At runtime the payload attempted DNS resolution to a C2 endpoint. The package has no lifecycle hooks — the malicious code runs when the module is imported, not at install time.

analyzed by
Leitwacht
first seen
Jul 27, 2026, 03:40 PM
analyzed
Jul 27, 2026, 03:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.