LWA-2026-11875 confirmed malware
sky-crown@1.0.0
Malicious code in sky-crown (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package ships an empty module (module.exports = {}) with no install scripts, but its README is casino-affiliate SEO spam promoting the gambling sites skycrowncasino[.]top and skycrown12[.]com (Infinite Blackjack / Australian play conditions marketing copy). The package is a spam/SEO artifact with no functional code; the only network references are the affiliate casino URLs embedded in the README.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 09:33 PM
- analyzed
- Sep 3, 2026, 09:33 PM
Related advisories
- easypanel-client@1.0.0
- windows-dev-bootstrap-vscode-part-1@0.2.0
- fieldbase-webapplication-buildtools@99.99.99
- mcp-consultasdeveiculos@0.0.1
- @bx-ui-framework/authentication@1.2.0
- @stellarshift/abi-tools@1.0.1
- tailwind-container-queries@0.1.1
- @cognition-ai/cli-linux-arm64@3000.6.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.