LWA-2026-11884 confirmed malware

jeet-city@1.0.0

Malicious code in jeet-city (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

jeet-city@1.0.0 is a README-only package containing casino-affiliate marketing content for "Jeet City Casino" (linking to jeetcity-australia.bet and jeetcity13[.]com). The package ships no executable code: index.js is an empty module export, there are no lifecycle scripts, no binaries, and no dependencies. It is a content-only package published as part of a broader malicious package-publishing campaign; installers receive no code and no network activity, but the package should not be trusted as a legitimate dependency.

analyzed by
Leitwacht
first seen
Sep 4, 2026, 12:04 AM
analyzed
Sep 4, 2026, 12:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.