LWA-2026-4211 confirmed malware

niieani@7.9.0

Malicious code in niieani (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Dependency-confusion stub: niieani@7.9.0 is a 497-byte package containing only package.json and a trivial index.js (console.log('Hello, world!')). Version 7.9.0 is a high-magnitude sentinel version intended to override legitimate lower-versioned packages during resolution. The manifest declares a dependency ui-styles-pkg pinned to the non-HTTPS custom registry URL hxxp://npm[.]jpartifacts[.]com/npm/niieani, listed in both dependencies and devDependencies; that custom registry could serve arbitrary code at install time. No inline lifecycle hooks or obfuscation; the attack surface is the dependency chain via the non-standard HTTP registry protocol.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 08:27 AM
analyzed
Jun 11, 2026, 08:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.