nx-app@9999.0.0-security-test
Malicious code in nx-app (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
nx-app@9999.0.0-security-test declares a dependency on itself resolved from the external non-registry URL hxxps://repo[.]securityctrl[.]com/nx-app. Installing the package causes npm to fetch and install a package from that attacker-controlled host, whose install scripts then execute. The package is published at the inflated version 9999.0.0-security-test, a dependency-confusion pattern intended to win resolution over a legitimate package of the same name.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 11:45 PM
- analyzed
- Aug 28, 2026, 11:46 PM
Related advisories
- grafeno-auth@1.0.0
- grafeno-pix@1.0.0
- grafeno-logger@1.0.0
- grafeno-config@1.0.0
- grafeno-core@1.0.0
- grafeno-utils@1.0.0
- grafeno-client@1.0.0
- grafeno-sdk@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.