MAL-2026-15689
Malicious code in lil-swisgom-hlepers (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (75aeaaa8ef6f56423bf517d9ff21cfed3a682701f306103f068b948e330f03db) package.json declares a dependency `lil-swisgom-hlepers-core` whose version specifier is a direct tarball URL on a third-party host (`https://registry.grivy-packages.com/lil-swisgom-hlepers-core/-/lil-swisgom-hlepers-core-49.9.9.tgz`) rather than a version resolved from the npm registry. On `npm install`, npm downloads and installs the arbitrary tarball from that host into the installer's dependency tree, bypassing npm registry review and scanning; any code the tarball ships (including install lifecycle scripts and module-load side effects) then runs on the installer's machine. The package name itself is a misspelling (`hlepers` for `helpers`), consistent with a typosquat lure funneling installers into pulling attacker-hosted tarball content.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for lil-swisgom-hlepers (npm). Pin to a known-safe version or switch to an alternative.