LWA-2026-11753 confirmed malware

helmify@0.0.1

Malicious code in helmify (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

helmify is a combosquat of the popular helmet Express security-headers middleware, shipping a verbatim copy of helmet's source code under a name designed to impersonate it (helmify vs helmet). The package metadata mirrors helmet's (homepage exhelmet[.]js[.]org, repository exhelmetjs/helmet, identical description and keywords). The current version 0.0.1 contains no injected payload, lifecycle hooks, or network activity — it is a clean copy of the legitimate helmet code. The risk is the impersonating package name and cloned metadata, which can lead installers to depend on the wrong package.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 08:15 PM
analyzed
Aug 29, 2026, 08:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.