LWA-2026-11885 confirmed malware
rolling-slots@1.0.0
Malicious code in rolling-slots (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
rolling-slots@1.0.0 is an inert package: its only code is an empty module export, with no install scripts, no dependencies, and no network activity. It ships a README containing casino-affiliate promotional content for "Rolling Slots Casino" with outbound links to rollingslotscasino[.]net and rollingslots70[.]com. The package performs no executable action on install; it is a content-only spam package.
- analyzed by
- Leitwacht
- first seen
- Sep 4, 2026, 12:17 AM
- analyzed
- Sep 4, 2026, 12:18 AM
Related advisories
- jeet-city@1.0.0
- richard-guide@1.0.0
- tailwind-aspect@0.4.2
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- slotozen-casino@1.0.0
- slotozen@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.