LWA-2026-10840 confirmed malware

statist-browser-typed-client-forge.front.metrics@0.0.1

Malicious code in statist-browser-typed-client-forge.front.metrics (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package statist-browser-typed-client-forge.front.metrics@0.0.1 is an empty placeholder module: its only source file (index.js) exports an empty object and the package declares no install scripts, no dependencies, and no executables. It ships no functional code despite describing itself as "Shared configuration and helpers". The package is a 385-byte stub with no observable runtime behaviour.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 12:28 PM
analyzed
Aug 8, 2026, 12:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.