LWA-2026-12117 confirmed malware
fast-xml-tagger@1.1.0
Malicious code in fast-xml-tagger (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
fast-xml-tagger@1.1.0 contains no executable code of its own — only a package.json. Its manifest declares an optionalDependency that causes npm to download and install a remote tarball from a non-registry host: hxxps://5k9o5gw5[.]instances[.]httpworkbench[.]com/test[.]tgz. Installing the package therefore fetches and installs an unverifiable third-party tarball from an external host, whose contents are not shipped with the package.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 03:02 AM
- analyzed
- Sep 14, 2026, 03:03 AM
Related advisories
- id79-client@1.1.79
- noblox-asset.js@7.4.1
- @biz44/id99-client@1.1.100
- @biz44/id95-client@1.1.96
- @biz44/id79-client@1.1.80
- @biz44/id44-client@1.1.44
- @biz44/id12-client@1.1.13
- @biz44/id10-client@1.1.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.