LWA-2026-11702 MAL-2026-15516 ↗ confirmed malware

nx-app@9999.0.0-security-test

Malicious code in nx-app (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

nx-app@9999.0.0-security-test declares a dependency on itself resolved from the external non-registry URL hxxps://repo[.]securityctrl[.]com/nx-app. Installing the package causes npm to fetch and install a package from that attacker-controlled host, whose install scripts then execute. The package is published at the inflated version 9999.0.0-security-test, a dependency-confusion pattern intended to win resolution over a legitimate package of the same name.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 11:45 PM
analyzed
Aug 28, 2026, 11:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.