-= Per source details. Do not edit below this line.=-
Package is published as htps-provider with a README copy-pasted verbatim from the legitimate Cosmos chain-registry project (advertising assets, chains, ibc exports and the same install/example snippets). The actual entrypoints do not expose that API: index.js and esm/index.mjs simply re-export HttpProvider from a runtime dependency named supersignaturenature (declared in package.json as "supersignaturenature": "^1.0.6"). esm/index.mjs performs a top-level static import of that dependency, so any ESM consumer that imports htps-provider immediately executes code from supersignaturenature. The name-and-README cover story, mismatched published API, and use of an obscurely-named third-party dependency as the sole runtime payload match the loader/stager half of a supply-chain attack, with the executable payload delivered through the transitively-installed dependency rather than this tarball. The chain.js files flagged by network/command patterns appear to be inert data/persistence modules unrelated to the loader path.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "GHSA-gcqr-3vw3-7fqm",
"import_time": "2026-08-29T20:22:41.193612745Z",
"modified_time": "2026-08-29T19:26:31Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "da0b78b1d8ceaa47ee7cfa5730bab8c05cfa585051fe78dee9464cad9f5f7588",
"source": "ghsa-malware"
},
{
"id": "IN-MAL-2026-019190",
"import_time": "2026-08-31T17:16:15.786339714Z",
"modified_time": "2026-08-31T16:53:21Z",
"sha256": "4ed7eca74d8fb188a8618c67facb5015d747e423ccdf4e51caae2e4e63f82ea2",
"source": "amazon-inspector",
"versions": [
"1.0.11"
]
},
{
"id": "IN-MAL-2026-019287",
"import_time": "2026-08-31T18:22:28.587835702Z",
"modified_time": "2026-08-31T17:59:51Z",
"sha256": "03112308b4e6b6d6ae28ed1fc891ad2b7902d12ba20dcf1e772d6ac8b6f48cc2",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "esm/index.mjs",
"sha256": "fa2c88f00db0be653609d23aea23e44f3a8e86e2c9792d8becf4484857c0833f",
"tlsh": "beb09276514770044757ab12b900cd83c7c801907822622032260736e8c3c000c6109e"
},
{
"path": "README.md",
"sha256": "cb686613fd6d572d8f59eedfb208fe602626ca9c9aef879f0e2e4a191685c6fe",
"tlsh": "7442a2f7cd10518b0b41deedb85670ede662b11ee644849cb96e42b0d3459e7c23fb48"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/htps-provider/MAL-2026-15567.json"