LWA-2026-4352 confirmed malware

npm-extension@45.0.0

Malicious code in npm-extension (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

npm-extension@45.0.0 is a dependency-confusion/combosquat package that declares a self-dependency pointing to the non-registry external URL hxxps://repo[.]securityctrl[.]com/npm-extension. During npm install this URL is fetched and resolved, letting the attacker serve arbitrary payloads. The shipped stub code is a decoy; the external-URL self-dependency is the attack vector, and the high version number (45.0.0) is typical of dependency-confusion takeovers.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 03:37 PM
analyzed
Jun 11, 2026, 03:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.