LWA-2026-10830 confirmed malware

statist-browser-typed-client-eventea.projects.tjuchebnik@0.0.1

Malicious code in statist-browser-typed-client-eventea.projects.tjuchebnik (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package is an empty placeholder module (index.js exports an empty object) with no lifecycle scripts, no dependencies, and no executable payload. It is published under a randomly-generated package name with no repository or documentation. The current version contains no code that runs on install and no network or file activity; it appears to be a staging artifact with no functional content.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 10:31 AM
analyzed
Aug 8, 2026, 10:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.