dsh-h3@0.0.0-stage
Malicious code in dsh-h3 (npm)
Analysis
dsh-h3@0.0.0-stage is a placeholder publish: the tarball contains only README.md (190 bytes) and package.json (138 bytes), 328 bytes unpacked, with no JavaScript, no install/lifecycle hooks, no bin entries, and no dependencies. The README describes it as a "temporary holding version" whose operational replacement is awaiting a staged release, i.e. the package name is being reserved ahead of a payload-bearing version. This version ships no executable code, no C2 endpoint, and no credential or file access; the analysis is metadata-only and no network or file IOCs could be extracted from it. Treat any later release of this name as untrusted.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 01:00 PM
- analyzed
- Oct 8, 2026, 01:01 PM
Related advisories
- @polymarkets/clob-client-v2@1.0.2
- @devmikets/hyperliquid-sdk@1.9.1
- @devmikets/hyperliquid-sdk@1.9.2
- @devmikets/hyperliquid-sdk@1.9.3
- @polymarkets/clob-client-v2@1.0.3
- neverthrow-js@4.5.1
- @polymarkets/clob-client-v2@1.0.4
- @devmikets/hyperliquid-sdk@1.9.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.