LWA-2026-12692 confirmed malware

tellyo-colours@0.0.0-stage

Malicious code in tellyo-colours (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

tellyo-colours@0.0.0-stage is a code-free placeholder publish that reserves the tellyo-colours package name ahead of a payload-bearing release. The tarball contains only package.json (declaring "stub": true and the description "Temporary package placeholder for staged publishing") and a README stating that an "operational version" has been submitted and is "awaiting a staged release". It declares no lifecycle scripts, no bin entries, no dependencies and ships no JavaScript, so this version executes nothing on install. Earlier versions published under this package name have shipped malicious code, and this publish re-establishes the name in preparation for a replacement release. No network indicators (C2 host, IP, URL, port) are present in this version; the analysis is metadata-only because there is no executable content in the tarball to read.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 07:47 AM
analyzed
Oct 8, 2026, 12:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.