LWA-2026-12318 confirmed malware
@tink/config@9.9.9
Malicious code in @tink/config (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
@tink/config@9.9.9 is a dependency-confusion stub: an empty placeholder package (index.js exports an empty object) published at version 9.9.9 on the scoped name @tink/config, a high version on a scoped internal-style name designed to collide with and be installed in place of a legitimate private package. The package ships no functional code, no repository, and no install hooks; its README states the implementation "ships in the next release." The version-squat on a scoped name is the supply-chain attack shape.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 09:18 AM
- analyzed
- Sep 22, 2026, 09:20 AM
Related advisories
- @tink/tink-link-core@9.9.10
- tlxbnhd@0.0.1
- @andrewstory18/is-real-odd@2.0.2
- @uh-platform/domain-widget@100.0.0
- @artistanbul/mta-frontend-footer@1.1.0
- lynxog@4.0.0
- chat-adapter-matrix@99.99.99
- @baanx/abis@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.