LWA-2026-5267 confirmed malware

test-delete-package@99.0.0-dummy

Malicious code in test-delete-package (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The tarball contains no executable code — only a minimal package.json with name "test-delete-package", artificially inflated version "99.0.0-dummy", and description "DUMMY VERSION - Package cleanup". The high version number is a known dependency-confusion and typosquatting preparation technique: by registering the package name at a version higher than any legitimate internal package, the actor ensures it will take priority if a project's dependency resolver accidentally matches against the public npm registry. The package currently executes no code, but the namespace is reserved and ready for future malicious publication under the same name.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 08:33 PM
analyzed
Jun 14, 2026, 08:34 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.