LWA-2026-12236 confirmed malware
@shared-web/tracking@9.9.9
Malicious code in @shared-web/tracking (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
A package published under the scoped name @shared-web/tracking at version 9.9.9 contains only an empty placeholder module (index.js exports an empty object) and a stub README, with no lifecycle hooks, dependencies, or executable code. The high version number on a generic internal-looking scoped name is consistent with dependency-confusion squatting: the package is planted to intercept installs that resolve to an internal/private package of the same name. No payload is present in this version; the squat itself is the supply-chain risk.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:03 AM
- analyzed
- Sep 18, 2026, 09:04 AM
Related advisories
- @shared-web/utils@9.9.10
- @shared-web/assets@9.9.10
- @shared-web/constants@9.9.9
- @shared-web/api@9.9.9
- @shared-runtime/config@9.9.9
- hardhat-devkit@2.3.6
- tailwindcss-form-utils@0.5.1
- tailwindcss-form-ui@0.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.