LWA-2026-12583 confirmed malware

css-reading-order-polyfill@0.0.0-stage

Malicious code in css-reading-order-polyfill (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

css-reading-order-polyfill@0.0.0-stage contains no executable code: the published tarball is 348 bytes unpacked and holds only package.json and README.md. The manifest sets "stub": true, describes itself as a "Temporary package placeholder for staged publishing", and uses the version string 0.0.0-stage; there is no repository, no license, no bin entry, no lifecycle hook, and no JavaScript. The README states the version is a temporary placeholder awaiting a staged release. This is a name-reservation publish: a plausible-sounding CSS polyfill name is claimed with an inert stub, positioned to be replaced by a functional payload in a later version. This version has no network activity and no IOCs (no C2 host, URL, IP, or dropped file) — the risk is the reserved package name and the expected follow-up release. Analysis of this version is metadata-only; no payload exists to characterise.

analyzed by
Leitwacht
first seen
Oct 5, 2026, 12:34 AM
analyzed
Oct 5, 2026, 06:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.