LWA-2026-12357 confirmed malware
roobet@1.0.0
Malicious code in roobet (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
An empty npm module (index.js exports an empty object) that ships a README containing casino-affiliate SEO marketing content for "Roobet Casino". The README embeds outbound links to roobet-in[.]com and an image hosted on i[.]ibb[.]co. No executable payload, lifecycle hooks, or network calls in the code itself; the package functions as SEO/affiliate spam promoting the casino.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 07:53 AM
- analyzed
- Sep 23, 2026, 07:54 AM
Related advisories
- spinsy-casino@1.0.0
- casinolabcasino@1.0.0
- casino-hermes@1.0.0
- casino-boomerang@1.0.0
- pistolo@1.0.0
- turbo-ws@1.0.0
- envforge2@1.0.1
- @tvg-mar/storyblok-bridge@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.