LWA-2026-11893 confirmed malware
thepokies-review@1.0.0
Malicious code in thepokies-review (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
thepokies-review@1.0.0 is a casino-affiliate spam package. It ships no executable code (index.js is an empty module export) and no install scripts, but its README is SEO marketing copy promoting the online casino The Pokies, embedding affiliate links to thepokies.games and thepokies119[.]net. The package's sole purpose is to drive traffic to the gambling affiliate destinations; it contains no functional library code.
- analyzed by
- Leitwacht
- first seen
- Sep 4, 2026, 02:41 AM
- analyzed
- Sep 4, 2026, 02:42 AM
Related advisories
- neospin@1.0.0
- 7bit-casino@1.0.0
- bitkingz@1.0.0
- rolling-slots@1.0.0
- jeet-city@1.0.0
- richard-guide@1.0.0
- tailwind-aspect@0.4.2
- 2nestjs@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.