MAL-2026-15689

    Dashboard / Malicious Package / MAL-2026-15689

    MAL-2026-15689

    Published: 24 Aug 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in lil-swisgom-hlepers (npm)

    Details: Source: amazon-inspector (75aeaaa8ef6f56423bf517d9ff21cfed3a682701f306103f068b948e330f03db) package.json declares a dependency `lil-swisgom-hlepers-core` whose version specifier is a direct tarball URL on a third-party host (`https://registry.grivy-packages.com/lil-swisgom-hlepers-core/-/lil-swisgom-hlepers-core-49.9.9.tgz`) rather than a version resolved from the npm registry. On `npm install`, npm downloads and installs the arbitrary tarball from that host into the installer's dependency tree, bypassing npm registry review and scanning; any code the tarball ships (including install lifecycle scripts and module-load side effects) then runs on the installer's machine. The package name itself is a misspelling (`hlepers` for `helpers`), consistent with a typosquat lure funneling installers into pulling attacker-hosted tarball content.

    Affected packages

    Package

    Name: lil-swisgom-hlepers

    Purl: pkg:npm/lil-swisgom-hlepers

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    49.9.9
    MAL-2026-15689 | CVE-DB