LWA-2026-11574 confirmed malware
sm-session@99.0.0
Malicious code in sm-session (npm)
T1195.002 · Compromise Software Supply ChainT1071.001 · Web Protocols
Analysis
sm-session@99.0.0 is published at version 99.0.0 with no functional code (index.js is an empty module). Its preinstall and postinstall hooks each issue an HTTP request to the raw IP 16[.]192[.]173[.]5 (paths /sm-session/pre and /sm-session/post) on every install, beaconing to a remote host. The package ships no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 23, 2026, 06:30 PM
- analyzed
- Aug 23, 2026, 06:30 PM
Related advisories
- modules-newline@0.0.6
- @fyxzpediaa/baileys@8.0.15
- kelly-sizing@0.1.0
- @next-fonts/font@1.0.1
- asistenyorstore@8.0.14
- express-session-handler@2.3.3
- chai-as-soul@2.3.6
- @httttt/mcp-npx-fetch-1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.