npm publish firehose · MITRE ATT&CK

Supply-chain malware, caught at publish.

Every newly published npm package, run through staged sandboxed analysis and classified by MITRE ATT&CK technique, streaming live as it publishes.

Scanned · 24h
101,153
npm publishes analysed
Malware confirmed
12,995
versions, feed-corroborated
Flagged pre-feed
8,644
feed-listed, we flagged first (max 118d)
Exclusive to us
·
confirmed, on no feed yet
ATT&CK techniques
192
distinct, this view

All counts are npm package versions. Confirmed: we classified it malicious and an external feed lists it too. Pre-feed: a feed lists it, and our detectors flagged it before the feed did. Exclusive: we confirmed it and no feed lists it yet. A version gets a public advisory only once its verdict has a written analysis, so the advisory index is smaller.

26.96 TB of package code analyzed

detections.stream
last 0
Free

Get alerted on your packages

List up to 50 npm packages you depend on. We'll email you the moment one is confirmed malicious by our triage, often days before it reaches public feeds.

  • Watch up to 50 of your dependencies, every version
  • Confirmed malware only, triage-verified, not raw detector noise
  • Free, double opt-in, one-click unsubscribe

Type to search, Enter or click to add. Not listed? Type the full name and press Enter.

Double opt-in: we email you to confirm. Unsubscribe anytime. No alerts until you confirm.

ATT&CK coverage, live

Each detection is mapped to the techniques its behaviour exhibits. Cells brighten as we observe them across the firehose.

Initial Access
195000
T1195.002 194937
Execution
159197
T1059 133602
T1059.007 27482
Persistence
37277
T1546.016 21881
T1574 832
Defense Evasion
83791
T1027 63606
T1140 36742
T1620 8308
T1480 552
T1036 12389
T1564 611
Credential Access
20555
T1552 780
T1552.001 19657
Discovery
12466
Collection
8127
T1005 8022
Command & Control
52994
T1071 2948
T1071.001 16422
T1571 2354
T1105 36917
T1102 2329
Exfiltration
3898
T1041 2862
T1567 1266
Impact
137
T1657 24

Confirmed malware, and why

Malicious packages independently corroborated by a public advisory feed, with our sandbox analysis and ATT&CK classification on top. Click any to read the reasoning.

Browse all confirmed advisories →

Full advisory → LWA-2026-12641

css-flow-render-shim@1.0.0 ships a bundled payload (package/payload.bundle.min.js) that executes when the module is required. It first deletes matching entries from require.cache (paths containing "payload", "rb_wixui", "rb_dsgnsys") to conceal its presence, then collects host reconnaissance by spawning child processes: whoami, id, uname -a, `env | head -100`, ifconfig / ip addr, and `cat /etc/hosts`. Each command's output is sent as a query string to the hardcoded collector hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (via fetch() with an https.get() fallback), together with the hostname, Node version, platform, pid and the package name. The environment dump can carry credentials and tokens present in the installer's environment. The remainder of the file is a Proxy-based stub exporting fake Wix thunderbolt registry names (thunderboltRegistry, corvidRegistry, editorRegistry, etc.) to make the package resemble a CSS/render shim; the declared entry point index.js is an empty module, so the payload is reached by requiring payload.bundle.min.js directly. IOCs: C2 hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (host webhook[.]site, port 443).

analyzed by Leitwacht · first seen 10/7/2026, 12:01:31 AM UTC · analyzed 10/7/2026, 12:01:51 AM UTC
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1070 · Indicator Removal
Full advisory → LWA-2026-12640
Full advisory → LWA-2026-12639
Full advisory → LWA-2026-12622
Full advisory → LWA-2026-12606
Full advisory → LWA-2026-12605
Full advisory → LWA-2026-12602
Full advisory → LWA-2026-12582
Full advisory → LWA-2026-12581