LWA-2026-11026 confirmed malware

dzvchorehui2@1.0.0

Malicious code in dzvchorehui2 (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package ships a single static HTML file (a Cloudflare "Just a moment..." bot-verification page) as its main entry, with no executable code, no install scripts, no dependencies, and no repository or documentation. It has no functional purpose as an npm package. No network endpoints or credential access were observed in the shipped content.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 02:18 AM
analyzed
Aug 12, 2026, 02:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.