LWA-2026-12697 confirmed malware

dsh-h3@0.0.0-stage

Malicious code in dsh-h3 (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

dsh-h3@0.0.0-stage is a placeholder publish: the tarball contains only README.md (190 bytes) and package.json (138 bytes), 328 bytes unpacked, with no JavaScript, no install/lifecycle hooks, no bin entries, and no dependencies. The README describes it as a "temporary holding version" whose operational replacement is awaiting a staged release, i.e. the package name is being reserved ahead of a payload-bearing version. This version ships no executable code, no C2 endpoint, and no credential or file access; the analysis is metadata-only and no network or file IOCs could be extracted from it. Treat any later release of this name as untrusted.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 01:00 PM
analyzed
Oct 8, 2026, 01:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.