LWA-2026-11651 confirmed malware
@flagship-io/openfeature-provider-js@1.0.0
Malicious code in @flagship-io/openfeature-provider-js (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package published under the name of the legitimate Flagship[.]io OpenFeature provider SDK (@flagship-io/openfeature-provider-js) but ships no functional code — only a package.json with a placeholder "test" description, no implementation, no lifecycle hooks, no repository, and no license. It is a namespace-claim/impersonation publish that reserves the legitimate vendor's package name; a later version could deliver a malicious payload to installers who believe they are installing the genuine SDK. No network IOCs present in this version.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 09:15 AM
- analyzed
- Aug 27, 2026, 09:16 AM
Related advisories
- date-fns-sync@1.0.0
- supersignaturenature@1.0.5
- external_deps_enjoyer@1.0.0
- chai-plus@6.2.5
- chai-as-otc@1.0.5
- mastercard-cc-sdk@1.0.0
- pantheon-secrets@1.0.0
- @atfm/typeface@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.