npm · Malicious package advisory
Malwarehyperliquid-composer
MAL-2026-15627
Malicious code in hyperliquid-composer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (1fb2b7d17a47aa4fcd585374f33063197f52d6ba8619e4105ae5a1d30331bb62) bin/cli.js (also declared as the package main) collects the installer's username via `whoami` / `os.userInfo()`, plus `os.hostname()` and platform, and POSTs them to the hardcoded Cloudflare Workers endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires on `require()` of the module or on CLI invocation, with no user consent or configuration. The package name resembles legitimate Hyperliquid tooling.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.