LWA-2026-11651 confirmed malware

@flagship-io/openfeature-provider-js@1.0.0

Malicious code in @flagship-io/openfeature-provider-js (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package published under the name of the legitimate Flagship[.]io OpenFeature provider SDK (@flagship-io/openfeature-provider-js) but ships no functional code — only a package.json with a placeholder "test" description, no implementation, no lifecycle hooks, no repository, and no license. It is a namespace-claim/impersonation publish that reserves the legitimate vendor's package name; a later version could deliver a malicious payload to installers who believe they are installing the genuine SDK. No network IOCs present in this version.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 09:15 AM
analyzed
Aug 27, 2026, 09:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.