LWA-2026-11026 confirmed malware
dzvchorehui2@1.0.0
Malicious code in dzvchorehui2 (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package ships a single static HTML file (a Cloudflare "Just a moment..." bot-verification page) as its main entry, with no executable code, no install scripts, no dependencies, and no repository or documentation. It has no functional purpose as an npm package. No network endpoints or credential access were observed in the shipped content.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 02:18 AM
- analyzed
- Aug 12, 2026, 02:18 AM
Related advisories
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
- bs58-33@6.0.1
- base65-33x@5.0.2
- neverthrow-core@1.1.2
- base65-15x@5.0.2
- base65-77x@5.0.2
- @openzeppelin-5/contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.