LWA-2026-11892 confirmed malware

neospin@1.0.0

Malicious code in neospin (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

neospin@1.0.0 is an inert casino-affiliate spam package. Its main module (index.js) is an empty export with no executable code, and the package ships no install scripts, no binaries, and no network activity. The only substantive content is a README.md of SEO-optimized promotional text for "Neospin Casino," a Dogecoin-themed online gambling site, containing affiliate links to neospin[.]casinologin[.]mobi and neospin4[.]com. The package performs no code execution and exfiltrates nothing; it exists to seed casino-affiliate marketing content into the npm registry.

analyzed by
Leitwacht
first seen
Sep 4, 2026, 01:44 AM
analyzed
Sep 4, 2026, 01:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.