LWA-2026-3977 confirmed malware
mintel-taskbar@45.0.0
Malicious code in mintel-taskbar (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
mintel-taskbar declares a self-dependency pointing to an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/mintel-taskbar). This is the classic dependency-confusion / self-dependency structure: npm resolves the self-dependency from the external URL at install, allowing the publisher to serve an arbitrary malicious tarball (which can carry postinstall hooks) at any time, while the registry publish itself stays inert.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 05:48 PM
- analyzed
- Jun 10, 2026, 05:50 PM
Related advisories
- firefly-utilities-helper@99.9.1
- websocket-slot@0.0.6
- metrica-chain@2.4.5
- meowmeow111@1.0.0
- meowmeow11001@1.0.0
- yelp-react-component-chaos@8.14.5
- prettier_v2@3.8.5
- win-build-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.