LWA-2026-12725 confirmed malware

wie888r@0.0.0-stage

Malicious code in wie888r (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

wie888r@0.0.0-stage is a code-free placeholder publish: the tarball contains only package.json (139 bytes) and README.md (190 bytes), 329 bytes unpacked, with no JavaScript, no bin entries, no lifecycle hooks, no dependencies and no optional dependencies. The README describes it as a "Temporary package placeholder for staged publishing" and the version is 0.0.0-stage. The same package name was previously used to distribute a confirmed-malicious version, and this publish re-establishes the name with no functional content. There is no executable payload in this version, so there are no network indicators, C2 hosts, dropped files or credential access to report — the analysis is metadata-only. The risk is that the name is being held for a follow-up publish that carries the payload; installers should treat any future version of wie888r as untrusted.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 07:32 PM
analyzed
Oct 8, 2026, 07:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.