Malicious code in @mypwn/hawkeye (npm)
The npm package @mypwn/hawkeye version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
- Disclosed
- Last updated
- Blast radius
- All users who installed @mypwn/hawkeye version 99.0.0
- Ecosystems
- Attack vectors
- Affected entities
- @mypwn/hawkeye · 99.0.0
The OpenSSF Package Analysis project identified @mypwn/hawkeye version 99.0.0 on npm as containing malicious code. The package was flagged for executing one or more commands associated with malicious behavior.\n\nThis incident was disclosed on 2026-07-29 via GitHub Security Advisory GHSA-28p4-h97c-j397 and tracked in the OpenSSF malicious-packages repository as MAL-2026-11157.\n\nAny system that installed this specific version of the package may have been compromised through execution of the malicious commands embedded in the package code.
Indicators of compromise
- Packages
- @mypwn/hawkeye@99.0.0
Remediation
- Immediately uninstall @mypwn/hawkeye version 99.0.0 from all systems
- Remove the package from package.json and lock files
- Audit systems that installed this version for signs of compromise
- Review npm audit logs for installation of this package
- Use npm to check for and remove any remaining instances of the malicious version
Sources
- GitHub Advisory GHSA-28p4-h97c-j397 · GitHub Advisory Database
Cite this entry
"Malicious code in @mypwn/hawkeye (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 29, 2026; last updated July 29, 2026. https://supplychainattack.org/incident/malicious-code-in-mypwn-hawkeye-npm-1p6avb
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @omniwatch-wick/cli
Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in lwp-web-client
The npm package lwp-web-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in flight-compare-analyzer
Malware was discovered in the npm package flight-compare-analyzer. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @peptide-unit/peptide-modify
Malware discovered in the npm package @peptide-unit/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package