LWA-2026-10830 confirmed malware
statist-browser-typed-client-eventea.projects.tjuchebnik@0.0.1
Malicious code in statist-browser-typed-client-eventea.projects.tjuchebnik (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package is an empty placeholder module (index.js exports an empty object) with no lifecycle scripts, no dependencies, and no executable payload. It is published under a randomly-generated package name with no repository or documentation. The current version contains no code that runs on install and no network or file activity; it appears to be a staging artifact with no functional content.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 10:31 AM
- analyzed
- Aug 8, 2026, 10:31 AM
Related advisories
- statist-browser-typed-client-eventea.projects.tj@0.0.1
- statist-browser-typed-client-eventea.projects.tdeal@0.0.1
- @reducers/projects@99.9.1
- statist-browser-typed-client-eventea.projects.pwainsurance@0.0.1
- statist-browser-typed-client-eventea.projects.pwakasko@0.0.1
- statist-browser-typed-client-eventea.projects.pwafamily@35.8.0
- @kolbo/mcp@1.57.1
- tailwindcss-motion-advanced@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.