LWA-2026-11883 confirmed malware
richard-guide@1.0.0
Malicious code in richard-guide (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
richard-guide@1.0.0 is an inert npm module whose only code is `module.exports = {};`. It contains no executable payload, no lifecycle hooks, and no network activity. Its sole content is a README of casino-promotion SEO spam advertising the Richard Casino online gambling site (richard-casino[.]net, richardcasino11[.]com). The package is a spam/SEO artifact with no functional code.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 11:38 PM
- analyzed
- Sep 3, 2026, 11:39 PM
Related advisories
- tailwind-aspect@0.4.2
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- slotozen-casino@1.0.0
- slotozen@1.0.0
- sky-crown@1.0.0
- easypanel-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.