VYPR

npm · Malicious package advisory

Malware

hyperliquid-composer

GHSA-c84j-qf44-w75w

Malicious code in hyperliquid-composer (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (1fb2b7d17a47aa4fcd585374f33063197f52d6ba8619e4105ae5a1d30331bb62)
bin/cli.js (also declared as the package main) collects the installer's username via `whoami` / `os.userInfo()`, plus `os.hostname()` and platform, and POSTs them to the hardcoded Cloudflare Workers endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires on `require()` of the module or on CLI invocation, with no user consent or configuration. The package name resembles legitimate Hyperliquid tooling.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/b9c9c442d6f4450955c7f85e197c76604ba12743/osv/malicious/npm/hyperliquid-composer/MAL-2026-15627.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/b9c9c442d6f4450955c7f85e197c76604ba12743/osv/malicious/npm/hyperliquid-composer/MAL-2026-15627.json
- https://www.npmjs.com/package/hyperliquid-composer/v/1.0.0
- https://github.com/advisories/GHSA-c84j-qf44-w75w

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.