LWA-2026-11574 confirmed malware

sm-session@99.0.0

Malicious code in sm-session (npm)

T1195.002 · Compromise Software Supply ChainT1071.001 · Web Protocols

Analysis

sm-session@99.0.0 is published at version 99.0.0 with no functional code (index.js is an empty module). Its preinstall and postinstall hooks each issue an HTTP request to the raw IP 16[.]192[.]173[.]5 (paths /sm-session/pre and /sm-session/post) on every install, beaconing to a remote host. The package ships no legitimate functionality.

analyzed by
Leitwacht
first seen
Aug 23, 2026, 06:30 PM
analyzed
Aug 23, 2026, 06:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.