LWA-2026-11516 confirmed malware
heheheshsds@2.0.0
Malicious code in heheheshsds (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
heheheshsds@2.0.0 is a static web-page package with no install-time code execution. It ships an HTML/SVG loader that fetches hxxps://unpkg[.]com/heheheshsds@latest/dist/index[.]html and injects it into the page DOM, plus a large bundled React web application (supabase realtime-js / phoenix channels). The package declares no lifecycle hooks and its main entry is empty; no credential or token theft was observed.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 11:15 PM
- analyzed
- Aug 19, 2026, 11:16 PM
Related advisories
- @wizloft/harness@0.1.1-alpha.3
- dev-env-check@1.0.3
- plugin-react-vite@2.1.2
- chai-as-gateway@7.1.5
- @oyo_tech/oyochat_user@100.0.0
- tailwind-extension-kit@1.3.2
- core-tailwindcss-utility@3.7.1
- libas-signal@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.