ai-texts-utils@1.0.3
Malicious code in ai-texts-utils (npm)
Analysis
The package ai-texts-utils@1.0.3 was published and then unpublished within a short window, leaving no manifest or tarball available for inspection. Analysis is metadata-only: no code, payload, or network behaviour could be observed, so no concrete IOCs are available. The publish-and-remove pattern is consistent with a package intended to be transient.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 05:02 PM
- analyzed
- Aug 19, 2026, 05:02 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.