LWA-2026-12234 confirmed malware

@shared-web/constants@9.9.9

Malicious code in @shared-web/constants (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@shared-web/constants@9.9.9 is a dependency-confusion/version-squat stub: a scoped package published at the sentinel version 9.9.9 containing only a placeholder entrypoint (module.exports = {}) with no implementation, no repository, no documentation of real functionality, and no dependency tree. The README states the full implementation "ships in the next release." The scoped name combined with the high sentinel version number is positioned to be resolved by automated dependency resolution in place of a legitimate internal package. No executable payload is present in this version.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 09:03 AM
analyzed
Sep 18, 2026, 09:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.