LWA-2026-4510 confirmed malware
paper-password-input@45.0.0
Malicious code in paper-password-input (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
paper-password-input@45.0.0 is a dependency-confusion package: a 538-byte placeholder whose index.js only logs a benign message, but whose package.json declares a self-dependency pointing to the attacker-controlled URL hxxps://repo[.]securityctrl[.]com/paper-password-input. When npm resolves the dependency tree on install, it fetches the real tarball from that external host. The README falsely claims to be an anti-dependency-confusion placeholder, which a genuine placeholder would not need to reference an external URL.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 12:59 AM
- analyzed
- Jun 12, 2026, 01:00 AM
Related advisories
- pampipes@1.1.9
- chai-web3-testkit@1.0.1
- req-parmas-valid@1.0.2
- mddriver@1.8.6
- vite-config-react@1.3.1
- openclaw-preview@2026.6.1
- one-intuit-help-system-utils@45.0.0
- internallib_v856@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.