LWA-2026-4510 confirmed malware

paper-password-input@45.0.0

Malicious code in paper-password-input (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

paper-password-input@45.0.0 is a dependency-confusion package: a 538-byte placeholder whose index.js only logs a benign message, but whose package.json declares a self-dependency pointing to the attacker-controlled URL hxxps://repo[.]securityctrl[.]com/paper-password-input. When npm resolves the dependency tree on install, it fetches the real tarball from that external host. The README falsely claims to be an anti-dependency-confusion placeholder, which a genuine placeholder would not need to reference an external URL.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 12:59 AM
analyzed
Jun 12, 2026, 01:00 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.