LWA-2026-7275 confirmed malware

@ai-vertical/ai-agent@1.0.0

Malicious code in @ai-vertical/ai-agent (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

@ai-vertical/ai-agent@1.0.0 is a remote-code-execution dropper. On require(), it fetches content from a GitHub gist (gist[.]github[.]com/aiverticalsolutions/7676451d2f972137d2482c4a8937a77a) via the GitHub API and passes the returned script text to eval(). The gist content is attacker-controlled and can be changed at any time, allowing arbitrary payload delivery to every system that installs this package.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 03:53 PM
analyzed
Jul 30, 2026, 03:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.