{"id":"MAL-2026-15689","summary":"Malicious code in lil-swisgom-hlepers (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (75aeaaa8ef6f56423bf517d9ff21cfed3a682701f306103f068b948e330f03db)\npackage.json declares a dependency `lil-swisgom-hlepers-core` whose version specifier is a direct tarball URL on a third-party host (`https://registry.grivy-packages.com/lil-swisgom-hlepers-core/-/lil-swisgom-hlepers-core-49.9.9.tgz`) rather than a version resolved from the npm registry. On `npm install`, npm downloads and installs the arbitrary tarball from that host into the installer's dependency tree, bypassing npm registry review and scanning; any code the tarball ships (including install lifecycle scripts and module-load side effects) then runs on the installer's machine. The package name itself is a misspelling (`hlepers` for `helpers`), consistent with a typosquat lure funneling installers into pulling attacker-hosted tarball content.\n","modified":"2026-09-04T01:00:04.780275459Z","published":"2026-08-24T16:57:41Z","database_specific":{"malicious-packages-origins":[{"sha256":"48bf599d7e976dd083e7ce4db9b65a513292caf083fababbf12ef96014eeec8b","source":"reversing-labs","versions":["49.9.9"],"id":"RLMA-2026-06305","import_time":"2026-09-01T11:17:32.136537547Z","modified_time":"2026-08-24T16:57:41Z"},{"versions":["49.9.9"],"id":"IN-MAL-2026-019395","import_time":"2026-09-04T00:45:55.591716668Z","modified_time":"2026-09-03T23:51:46Z","sha256":"75aeaaa8ef6f56423bf517d9ff21cfed3a682701f306103f068b948e330f03db","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/lil-swisgom-hlepers/v/49.9.9"}],"affected":[{"package":{"name":"lil-swisgom-hlepers","ecosystem":"npm","purl":"pkg:npm/lil-swisgom-hlepers"},"versions":["49.9.9"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"9e78e0fc95f06634d0893ef56649eb89a3b1a4edbec9bf5deaf9bd727944e458","tlsh":"1401211299624f33a5818d5024c102c92ad68b4b038c7c86a283012d22bafafa4fb19d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/lil-swisgom-hlepers/MAL-2026-15689.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}