LWA-2026-12252 confirmed malware
melbet-cm@1.0.0
Malicious code in melbet-cm (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
melbet-cm@1.0.0 ships no functional code: its entry point is an empty module (module.exports = {}) and it contains no install scripts, executables, or dependencies. The package consists solely of a French-language SEO article promoting the Melbet online-gambling site, linking to 1monde2sport[.]com and embedding an image from i[.]ibb[.]co. It is an SEO/spam package with no executable payload; the analysis is metadata-only as no code artifacts are present to inspect.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 07:57 PM
- analyzed
- Sep 18, 2026, 07:58 PM
Related advisories
- tailwind-form-styles@0.5.1
- @shared-web/constants@9.9.9
- @shared-web/modules@9.9.9
- @shared-runtime/api@9.9.9
- @shared-web/tracking@9.9.9
- @shared-web/api@9.9.9
- @shared-runtime/config@9.9.9
- hardhat-devkit@2.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.