LWA-2026-12318 confirmed malware

@tink/config@9.9.9

Malicious code in @tink/config (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@tink/config@9.9.9 is a dependency-confusion stub: an empty placeholder package (index.js exports an empty object) published at version 9.9.9 on the scoped name @tink/config, a high version on a scoped internal-style name designed to collide with and be installed in place of a legitimate private package. The package ships no functional code, no repository, and no install hooks; its README states the implementation "ships in the next release." The version-squat on a scoped name is the supply-chain attack shape.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 09:18 AM
analyzed
Sep 22, 2026, 09:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.