LWA-2026-12280 MAL-2026-16352 ↗ confirmed malware

@baanx/blockchain-config@9.9.9

Malicious code in @baanx/blockchain-config (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@baanx/blockchain-config@9.9.9 is a dependency-confusion squat: a placeholder package published under a scoped name at version 9.9.9 with no implementation (index.js exports an empty object, no lifecycle hooks, no repository, no dependencies). The package ships only a stub entrypoint and a smoke test, consistent with squatting a scoped package name to intercept installs intended for a private/internal package. No executable payload is present in this version.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 12:33 PM
analyzed
Sep 20, 2026, 12:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.