kartykp-token-pkg@1.0.2
Malicious code in kartykp-token-pkg (npm)
Analysis
kartykp-token-pkg@1.0.2 was published to the npm registry and then unpublished within the same fetch window, so no manifest or package tarball remains retrievable for inspection. The package name is token-themed and the immediate publish-then-yank timing is consistent with a publish-and-burn pattern. Because the artifact was removed before it could be captured, no code-level behaviour or network indicators could be established; this advisory is metadata-only.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 10:27 PM
- analyzed
- Sep 15, 2026, 10:28 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.