LWA-2026-12326 confirmed malware

@tvg-mar/storyblok-bridge@9.9.9

Malicious code in @tvg-mar/storyblok-bridge (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion squat: a high-version (9.9.9) stub published on the scoped name @tvg-mar/storyblok-bridge, designed to be resolved by an internal build expecting a private package of that name. The published tarball ships only an empty placeholder module (module.exports = {}) with no implementation, no repository, and no lifecycle hooks — a name-reservation stub rather than a functional package.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 04:54 PM
analyzed
Sep 22, 2026, 04:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.