LWA-2026-11678 confirmed malware

melbet-ivoire@1.0.0

Malicious code in melbet-ivoire (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package ships an empty module (index.js exports nothing) whose only content is a French-language SEO-spam README promoting a betting site (Melbet Côte d'Ivoire). The README embeds affiliate links to paintedponyneedlepoint[.]com and an image hosted on i[.]ibb[.]co. No executable payload, lifecycle hooks, or network activity are present in the code; the package functions purely as an SEO/affiliate-marketing vehicle.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 05:32 AM
analyzed
Aug 28, 2026, 05:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.