LWA-2026-11678 confirmed malware
melbet-ivoire@1.0.0
Malicious code in melbet-ivoire (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package ships an empty module (index.js exports nothing) whose only content is a French-language SEO-spam README promoting a betting site (Melbet Côte d'Ivoire). The README embeds affiliate links to paintedponyneedlepoint[.]com and an image hosted on i[.]ibb[.]co. No executable payload, lifecycle hooks, or network activity are present in the code; the package functions purely as an SEO/affiliate-marketing vehicle.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 05:32 AM
- analyzed
- Aug 28, 2026, 05:32 AM
Related advisories
- @bx-ui-framework/common@15.0.0
- manager-thedate@1.0.16
- vitest-chalk-pro@10.0.7
- shadowmd@8.6.87
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- tailwindcss-form-styles@0.5.15
- tailwindcss-3d-animate@1.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.