LWA-2026-12299 confirmed malware

@artistanbul/mta-frontend-footer@1.1.0

Malicious code in @artistanbul/mta-frontend-footer (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@artistanbul/mta-frontend-footer is a combosquat of the official Open edX frontend footer component (@edx/frontend-component-footer): the same React footer source tree republished under the @artistanbul scope. The package ships the cloned component code with no install hooks or network behavior in this version, but impersonates a well-known legitimate package name to be picked up as a dependency. Verify the package name/scope against the official @edx/frontend-component-footer before installing.

analyzed by
Leitwacht
first seen
Sep 21, 2026, 11:55 AM
analyzed
Sep 21, 2026, 11:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.