LWA-2026-11876 confirmed malware

slotozen@1.0.0

Malicious code in slotozen (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

slotozen@1.0.0 is an inert SEO-spam package: its only code is an empty module export, with no install scripts, no binaries, and no dependencies. The package ships a README that promotes the online casino sites slotozencasino[.]net and slotozen8[.]com. It contains no executable payload; the finding is based on the package's association with a publisher known for publishing malicious packages.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 09:48 PM
analyzed
Sep 3, 2026, 09:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.