LWA-2026-11904 confirmed malware
dazaar-guild@1.0.0
Malicious code in dazaar-guild (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
dazaar-guild@1.0.0 is an empty package containing only a package.json manifest with no executable code, no lifecycle hooks, no dependencies, and no bin entries. Its only script is a test stub that echoes an error and exits. The package name resembles the dazaar ecosystem and appears to be a name reservation with no functional content; no network activity, file access, or credential handling is present in the tarball.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 03:41 PM
- analyzed
- Sep 5, 2026, 03:42 PM
Related advisories
- tailwindcss-ratio-styles@0.3.2
- ulid-intel@2.12.3
- thepokies-review@1.0.0
- neospin@1.0.0
- 7bit-casino@1.0.0
- bitkingz@1.0.0
- rolling-slots@1.0.0
- jeet-city@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.