LWA-2026-12117 confirmed malware

fast-xml-tagger@1.1.0

Malicious code in fast-xml-tagger (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

fast-xml-tagger@1.1.0 contains no executable code of its own — only a package.json. Its manifest declares an optionalDependency that causes npm to download and install a remote tarball from a non-registry host: hxxps://5k9o5gw5[.]instances[.]httpworkbench[.]com/test[.]tgz. Installing the package therefore fetches and installs an unverifiable third-party tarball from an external host, whose contents are not shipped with the package.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 03:02 AM
analyzed
Sep 14, 2026, 03:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.