LWA-2026-11889 confirmed malware
bitkingz@1.0.0
Malicious code in bitkingz (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
bitkingz@1.0.0 is an inert casino-affiliate SEO spam package. It ships an empty index.js (module.exports = {}) with no functional code, no install hooks, and no dependencies. Its README is affiliate-marketing content for BitKingz Casino, embedding outbound links to bitkingz[.]casinologin[.]mobi and bitkingz[.]com/en-AU. The package provides no functionality and exists solely as a spam/SEO vehicle.
- analyzed by
- Leitwacht
- first seen
- Sep 4, 2026, 01:38 AM
- analyzed
- Sep 4, 2026, 01:39 AM
Related advisories
- rolling-slots@1.0.0
- jeet-city@1.0.0
- richard-guide@1.0.0
- tailwind-aspect@0.4.2
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- slotozen-casino@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.