LWA-2026-11885 confirmed malware

rolling-slots@1.0.0

Malicious code in rolling-slots (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

rolling-slots@1.0.0 is an inert package: its only code is an empty module export, with no install scripts, no dependencies, and no network activity. It ships a README containing casino-affiliate promotional content for "Rolling Slots Casino" with outbound links to rollingslotscasino[.]net and rollingslots70[.]com. The package performs no executable action on install; it is a content-only spam package.

analyzed by
Leitwacht
first seen
Sep 4, 2026, 12:17 AM
analyzed
Sep 4, 2026, 12:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.