niieani@7.9.0
Malicious code in niieani (npm)
Analysis
Dependency-confusion stub: niieani@7.9.0 is a 497-byte package containing only package.json and a trivial index.js (console.log('Hello, world!')). Version 7.9.0 is a high-magnitude sentinel version intended to override legitimate lower-versioned packages during resolution. The manifest declares a dependency ui-styles-pkg pinned to the non-HTTPS custom registry URL hxxp://npm[.]jpartifacts[.]com/npm/niieani, listed in both dependencies and devDependencies; that custom registry could serve arbitrary code at install time. No inline lifecycle hooks or obfuscation; the attack surface is the dependency chain via the non-standard HTTP registry protocol.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 08:27 AM
- analyzed
- Jun 11, 2026, 08:30 AM
Related advisories
- ng-search-api@99.9.1
- ts-ecro@0.0.6
- parket-slot@0.0.6
- tailwind-typography-plus@2.1.0
- linux-ci-utils@1.0.0
- myria-core-sdk@0.0.248
- motion-lib@2.3.5
- hex-type@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.