LWA-2026-3977 confirmed malware

mintel-taskbar@45.0.0

Malicious code in mintel-taskbar (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

mintel-taskbar declares a self-dependency pointing to an attacker-controlled external URL (hxxps://repo[.]securityctrl[.]com/mintel-taskbar). This is the classic dependency-confusion / self-dependency structure: npm resolves the self-dependency from the external URL at install, allowing the publisher to serve an arbitrary malicious tarball (which can carry postinstall hooks) at any time, while the registry publish itself stays inert.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 05:48 PM
analyzed
Jun 10, 2026, 05:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.