LWA-2026-12232 confirmed malware
@shared-runtime/config@9.9.9
Malicious code in @shared-runtime/config (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@shared-runtime/config@9.9.9 is a dependency-confusion/version-squat package: a scoped name published at a high sentinel version (9.9.9) containing only a 650-byte placeholder stub (index.js exports an empty object) with no real implementation. The package is designed to be resolved by internal dependency resolution in place of a legitimate shared-runtime config module, and the placeholder entrypoint indicates a staged delivery where the actual payload is deferred to a later version. No repository, no documentation of substance.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:03 AM
- analyzed
- Sep 18, 2026, 09:04 AM
Related advisories
- @shared-runtime/modules@9.9.10
- @shared-runtime/api@9.9.9
- hardhat-devkit@2.3.6
- tailwindcss-form-utils@0.5.1
- tailwindcss-form-ui@0.5.1
- @vitemirrorte/element-plus-vite-cli@2.9.1
- chai-as-core@7.0.8
- hardhat-core@2.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.