MAL-2026-15567

    Dashboard / Malicious Package / MAL-2026-15567

    MAL-2026-15567

    Published: 29 Aug 2026Last Modified: 31 Aug 2026Aliases: 
    GHSA-gcqr-3vw3-7fqm

    Summary: Malicious code in htps-provider (npm)

    Details: Source: amazon-inspector (4ed7eca74d8fb188a8618c67facb5015d747e423ccdf4e51caae2e4e63f82ea2) Package is published as htps-provider with a README copy-pasted verbatim from the legitimate Cosmos chain-registry project (advertising assets, chains, ibc exports and the same install/example snippets). The actual entrypoints do not expose that API: index.js and esm/index.mjs simply re-export HttpProvider from a runtime dependency named supersignaturenature (declared in package.json as "supersignaturenature": "^1.0.6"). esm/index.mjs performs a top-level static import of that dependency, so any ESM consumer that imports htps-provider immediately executes code from supersignaturenature. The name-and-README cover story, mismatched published API, and use of an obscurely-named third-party dependency as the sole runtime payload match the loader/stager half of a supply-chain attack, with the executable payload delivered through the transitively-installed dependency rather than this tarball. The chain.js files flagged by network/command patterns appear to be inert data/persistence modules unrelated to the loader path. Source: ghsa-malware (da0b78b1d8ceaa47ee7cfa5730bab8c05cfa585051fe78dee9464cad9f5f7588) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    Affected packages

    Package

    Name: htps-provider

    Purl: pkg:npm/htps-provider

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.11
    1.0.10