LWA-2026-12279 MAL-2026-16351 ↗ confirmed malware

@baanx/abis@9.9.9

Malicious code in @baanx/abis (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@baanx/abis@9.9.9 is a dependency-confusion squat: a scoped package published at version 9.9.9 claiming to be an EVM smart-contract ABI library, but containing only an empty placeholder entrypoint (module.exports = {}) with no implementation. The high version number on the scoped name is designed to win dependency resolution against a legitimate internal @baanx/abis package. This version ships no executable payload; the placeholder claims the name for a later release.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 12:32 PM
analyzed
Sep 20, 2026, 12:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.