LWA-2026-4222 confirmed malware
no-date-parsing@2.2.0
Malicious code in no-date-parsing (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
no-date-parsing@2.2.0 is a typosquat of common date-parsing libraries whose manifest declares dependencies.inline = hxxp://npm[.]artifactsnpm[.]com/npm/no-date-parsing, an HTTP URL pointing to a non-standard, attacker-controlled npm registry. The shipped index.js is a trivial Hello World stub, indicating the real payload is served from that external registry during dependency resolution.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:46 AM
- analyzed
- Jun 11, 2026, 09:47 AM
Related advisories
- firefly-utilities-helper@99.9.1
- optional-cpu-features@1.0.3
- @morpho-blue-liquidation-bot/data-providers@2.0.0
- @morpho-blue-liquidation-bot/pricers@2.0.0
- kepler@1.0.999
- test-flow-entire3@1.0.0
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.