LWA-2026-4352 confirmed malware
npm-extension@45.0.0
Malicious code in npm-extension (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
npm-extension@45.0.0 is a dependency-confusion/combosquat package that declares a self-dependency pointing to the non-registry external URL hxxps://repo[.]securityctrl[.]com/npm-extension. During npm install this URL is fetched and resolved, letting the attacker serve arbitrary payloads. The shipped stub code is a decoy; the external-URL self-dependency is the attack vector, and the high version number (45.0.0) is typical of dependency-confusion takeovers.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 03:37 PM
- analyzed
- Jun 11, 2026, 03:37 PM
Related advisories
- npm-bs58.js@2.0.2
- npmamzs@1.1.4
- npm-doc-dev@1.0.9
- ecto-rust-read-f3a9c1@1.0.2
- chalk-plus-js@7.0.4
- express-initial@12.1.7
- node-pino@2.3.2
- sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.