LWA-2026-12282 MAL-2026-16486 ↗ confirmed malware

@baanx/domain@9.9.9

Malicious code in @baanx/domain (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@baanx/domain@9.9.9 is a dependency-confusion stub: a scoped package published at sentinel version 9.9.9 that ships an empty placeholder entrypoint (module.exports = {}) with no implementation, no repository, and no documentation of real functionality. The high version on a scoped name is consistent with dependency-confusion squatting, where a package is published to be picked up by tooling that resolves an internal/private package name to the public registry. No executable payload is present in this version.

analyzed by
Leitwacht
first seen
Sep 20, 2026, 12:33 PM
analyzed
Sep 20, 2026, 12:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.