LWA-2026-11991 confirmed malware
billion-context-dsh-patch@0.2.21-patch.1
Malicious code in billion-context-dsh-patch (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
billion-context-dsh-patch is a combosquat of the legitimate DeepSeek Harness plugin billion-context-dsh, published under a "-patch" suffix. The package ships a TypeScript context-compression engine (ACP) with no install hooks, no network activity, and no credential access in the shipped code; it impersonates the real billion-context-dsh package name to be mistaken for the upstream plugin. Installers should verify they are depending on the genuine billion-context-dsh package rather than this lookalike.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 10:02 AM
- analyzed
- Sep 10, 2026, 10:03 AM
Related advisories
- @reaxuse/integrations@0.0.1
- @reaxuse/firebase@0.0.1
- @reaxuse/core@0.0.1
- @reaxuse/shared@0.0.1
- @reaxuse/rxjs@0.0.1
- @reaxuse/router@0.0.1
- etoro-aggregator@999.0.0
- etoro-cashout@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.