LWA-2026-4199 confirmed malware
next-form-helper@1.0.2
Malicious code in next-form-helper (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
next-form-helper@1.0.2 declares a circular self-dependency ("next-form-helper":"^1.0.1") that causes npm install to loop or fail during dependency resolution. Its postinstall hook runs `node rickroll.js`, which opens a YouTube video in the browser via the `open` package. No credential or token theft is present; this is a small (648-byte) install-disrupting nuisance/abuse package.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 06:27 AM
- analyzed
- Jun 11, 2026, 06:28 AM
Related advisories
- pocteszep@1.0.0
- @monitoring-lib/error-tracking@9999.0.0
- mermaid-v11@9999.0.0
- myria-core-sdk@0.0.248
- @coze-common/chat-area@99.1.1
- mw-filesystem-events-nodream_compat@99.99.99
- mw-filesystem-events-nodream-es6@0.0.32
- mw-filesystem-events-nodream@0.0.32
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.