LWA-2026-12235 confirmed malware
@shared-web/modules@9.9.9
Malicious code in @shared-web/modules (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@shared-web/modules@9.9.9 is a dependency-confusion squat: a scoped package named @shared-web/modules published at version 9.9.9 with no real implementation (an empty placeholder entrypoint, no lifecycle hooks, no dependencies, no binaries). The high version on a generic scoped name is designed to be selected by package-manager dependency resolution in place of a legitimate internal package of the same name, hijacking the dependency. The package ships no functional code.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:03 AM
- analyzed
- Sep 18, 2026, 09:04 AM
Related advisories
- @shared-web/utils@9.9.10
- @shared-web/assets@9.9.10
- @shared-web/constants@9.9.9
- @shared-runtime/api@9.9.9
- @shared-web/tracking@9.9.9
- @shared-web/api@9.9.9
- @shared-runtime/config@9.9.9
- hardhat-devkit@2.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.