VDB
Sign up

MAL-2026-15689

Malicious code in lil-swisgom-hlepers (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (75aeaaa8ef6f56423bf517d9ff21cfed3a682701f306103f068b948e330f03db) package.json declares a dependency `lil-swisgom-hlepers-core` whose version specifier is a direct tarball URL on a third-party host (`https://registry.grivy-packages.com/lil-swisgom-hlepers-core/-/lil-swisgom-hlepers-core-49.9.9.tgz`) rather than a version resolved from the npm registry. On `npm install`, npm downloads and installs the arbitrary tarball from that host into the installer's dependency tree, bypassing npm registry review and scanning; any code the tarball ships (including install lifecycle scripts and module-load side effects) then runs on the installer's machine. The package name itself is a misspelling (`hlepers` for `helpers`), consistent with a typosquat lure funneling installers into pulling attacker-hosted tarball content.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lil-swisgom-hlepers

No fixed version published yet for lil-swisgom-hlepers (npm). Pin to a known-safe version or switch to an alternative.

References