VYPR

npm · Malicious package advisory

Malware

hyperliquid-composer

MAL-2026-15627

Malicious code in hyperliquid-composer (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1fb2b7d17a47aa4fcd585374f33063197f52d6ba8619e4105ae5a1d30331bb62)
bin/cli.js (also declared as the package main) collects the installer's username via `whoami` / `os.userInfo()`, plus `os.hostname()` and platform, and POSTs them to the hardcoded Cloudflare Workers endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires on `require()` of the module or on CLI invocation, with no user consent or configuration. The package name resembles legitimate Hyperliquid tooling.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.