LWA-2026-12233 confirmed malware

@shared-web/api@9.9.9

Malicious code in @shared-web/api (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@shared-web/api@9.9.9 is a dependency-confusion squat: a 642-byte package published at the high sentinel version 9.9.9 under a plausible internal/private name (@shared-web/api), with an empty placeholder entrypoint (module.exports = {}) and no repository or documentation. The high version on a plausible private-scope name is designed to win dependency-confusion resolution and be installed into builds that reference the internal @shared-web/api package. The package ships no functional implementation — only a stub entrypoint and a smoke test — consistent with a squat stub published ahead of a payload.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 09:03 AM
analyzed
Sep 18, 2026, 09:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.