LWA-2026-12749 confirmed malware

dsh-hono@0.0.0-stage

Malicious code in dsh-hono (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

dsh-hono@0.0.0-stage is a placeholder publish, not a functional package: the tarball is 330 bytes and contains only package.json and README.md, with no JavaScript, no bin entries, no dependencies, and no install lifecycle hooks. The README describes it as a "temporary holding version" awaiting a staged release, and the version tag 0.0.0-stage marks it as a name-reservation publish. The package contains no executable code, so there is no payload, network endpoint, credential access, or persistence mechanism to report in this version; no code-level indicators exist. The name dsh-hono should be treated as reserved for a staged follow-up release.

analyzed by
Leitwacht
first seen
Oct 9, 2026, 04:54 AM
analyzed
Oct 9, 2026, 04:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.