LWA-2026-10824 confirmed malware

statist-browser-typed-client-eventea.projects.pwainsurance@0.0.1

Malicious code in statist-browser-typed-client-eventea.projects.pwainsurance (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

An empty placeholder package (394 bytes) published under a name resembling a legitimate platform-integration client ("statist-browser-typed-client-eventea.projects.pwainsurance", described as "Platform integration layer"). The package contains no functional code: index.js only exports an empty object and there are no install scripts, dependencies, or network activity. It is an inert stub with no executable payload.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 07:39 AM
analyzed
Aug 8, 2026, 07:42 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.