LWA-2026-11904 confirmed malware

dazaar-guild@1.0.0

Malicious code in dazaar-guild (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

dazaar-guild@1.0.0 is an empty package containing only a package.json manifest with no executable code, no lifecycle hooks, no dependencies, and no bin entries. Its only script is a test stub that echoes an error and exits. The package name resembles the dazaar ecosystem and appears to be a name reservation with no functional content; no network activity, file access, or credential handling is present in the tarball.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 03:41 PM
analyzed
Sep 5, 2026, 03:42 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.