LWA-2026-12299 confirmed malware
@artistanbul/mta-frontend-footer@1.1.0
Malicious code in @artistanbul/mta-frontend-footer (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@artistanbul/mta-frontend-footer is a combosquat of the official Open edX frontend footer component (@edx/frontend-component-footer): the same React footer source tree republished under the @artistanbul scope. The package ships the cloned component code with no install hooks or network behavior in this version, but impersonates a well-known legitimate package name to be picked up as a dependency. Verify the package name/scope against the official @edx/frontend-component-footer before installing.
- analyzed by
- Leitwacht
- first seen
- Sep 21, 2026, 11:55 AM
- analyzed
- Sep 21, 2026, 11:56 AM
Related advisories
- lynxog@4.0.0
- chat-adapter-matrix@99.99.99
- @baanx/abis@9.9.9
- @baanx/blockchain-config@9.9.9
- @baanx/domain@9.9.9
- @baanx/common@9.9.9
- @dbbhk/ui-components@99.0.0
- ndmcmsujey@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.