MAL-2026-15567
Dashboard / Malicious Package / MAL-2026-15567
MAL-2026-15567
Summary: Malicious code in htps-provider (npm)
Details: Source: amazon-inspector (4ed7eca74d8fb188a8618c67facb5015d747e423ccdf4e51caae2e4e63f82ea2) Package is published as htps-provider with a README copy-pasted verbatim from the legitimate Cosmos chain-registry project (advertising assets, chains, ibc exports and the same install/example snippets). The actual entrypoints do not expose that API: index.js and esm/index.mjs simply re-export HttpProvider from a runtime dependency named supersignaturenature (declared in package.json as "supersignaturenature": "^1.0.6"). esm/index.mjs performs a top-level static import of that dependency, so any ESM consumer that imports htps-provider immediately executes code from supersignaturenature. The name-and-README cover story, mismatched published API, and use of an obscurely-named third-party dependency as the sole runtime payload match the loader/stager half of a supply-chain attack, with the executable payload delivered through the transitively-installed dependency rather than this tarball. The chain.js files flagged by network/command patterns appear to be inert data/persistence modules unrelated to the loader path. Source: ghsa-malware (da0b78b1d8ceaa47ee7cfa5730bab8c05cfa585051fe78dee9464cad9f5f7588) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://github.com/advisories/GHSA-gcqr-3vw3-7fqm, https://www.npmjs.com/package/htps-provider/v/1.0.11, https://www.npmjs.com/package/htps-provider/v/1.0.10
Affected packages
Package
Name: htps-provider
Purl: pkg:npm/htps-provider
Affected ranges
Type: SEMVER
Events:
