tellyo-colours@0.0.0-stage
Malicious code in tellyo-colours (npm)
Analysis
tellyo-colours@0.0.0-stage is a code-free placeholder publish that reserves the tellyo-colours package name ahead of a payload-bearing release. The tarball contains only package.json (declaring "stub": true and the description "Temporary package placeholder for staged publishing") and a README stating that an "operational version" has been submitted and is "awaiting a staged release". It declares no lifecycle scripts, no bin entries, no dependencies and ships no JavaScript, so this version executes nothing on install. Earlier versions published under this package name have shipped malicious code, and this publish re-establishes the name in preparation for a replacement release. No network indicators (C2 host, IP, URL, port) are present in this version; the analysis is metadata-only because there is no executable content in the tarball to read.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 07:47 AM
- analyzed
- Oct 8, 2026, 12:06 PM
Related advisories
- @polymarkets/clob-client-v2@1.0.5
- node-env-resolve@1.2.3
- @devmikets/hyperliquid-sdk@1.9.4
- chai-as-indexed@6.0.5
- @yaszz/bail@1.0.0
- tensorlake@0.5.144
- dzyclutch-baileys@1.1.21
- dzyclutch-baileys@1.1.16
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.