LWA-2026-7275 confirmed malware
@ai-vertical/ai-agent@1.0.0
Malicious code in @ai-vertical/ai-agent (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
@ai-vertical/ai-agent@1.0.0 is a remote-code-execution dropper. On require(), it fetches content from a GitHub gist (gist[.]github[.]com/aiverticalsolutions/7676451d2f972137d2482c4a8937a77a) via the GitHub API and passes the returned script text to eval(). The gist content is attacker-controlled and can be changed at any time, allowing arbitrary payload delivery to every system that installs this package.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 03:53 PM
- analyzed
- Jul 30, 2026, 03:55 PM
Related advisories
- akamai-sensorv2@1.0.0
- akamai-sensorv1@1.0.0
- native-hello-plugin@1.2.0
- streak-metric-core@1.0.0
- react-fast-refresh-helper@1.2.6
- rollup-plugins-check@0.0.1
- multi-acct@1.0.0
- merchantweb-lang-cookie-reset@0.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.