lovable-tagernpm
Advisory published Updated
lovable-tager is a confirmed malicious npm package (MAL-2026-10088) that typosquats a legitimate package to trick installs (malicious versions 1.4.0, 1.4.1). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in lovable-tager (npm)
What this malware does
lovable-tager is a single-character-deletion typosquat of the legitimate Vite plugin lovable-tagger. The ESM entry dist/index.js (referenced by main) contains the clean plugin code followed by ~6 KB of tab padding and then an appended obfuscator.io-style permutation-obfuscated IIFE. On module load, the IIFE assigns global.require, global.__dirname, and global.__filename, derives Function via a deshuffled constructor lookup, constructs a new Function from an obfuscated string body, and immediately invokes it. The sibling CJS build dist/index.cjs, produced from the same source, contains only the clean plugin code with no such trailer — indicating the payload was smuggled into the published tarball after the normal build ran, hidden behind tab padding that suppresses it in most editors and diff views. Any project that adds the mistyped name to its Vite config executes attacker-controlled code inside the developer's Node process at plugin-load time, with the ability to reach require, the filesystem, and the network of the build host.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for lovable-tager (2 malicious versions).
If you installed it — respond
lovable-tager is a typosquat — you almost certainly intended a legitimately-named package. Remove lovable-tager, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If lovable-tager was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks lovable-tager-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.