LWA-2026-5270 confirmed malware
test-multi-versions@1.0.0
Malicious code in test-multi-versions (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Metadata-only finding: the package contains only a package.json file with no executable code, no lifecycle scripts, and no binary entries. The package name suggests a test/namespace-reservation pattern. No network IOCs, no exfiltration behavior, and no malicious code are present in this version. The significance is that the package is an empty stub published under a name that appears to be a namespace reservation, with no other observable behavior to describe at this version.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 09:32 PM
- analyzed
- Jun 14, 2026, 09:33 PM
Related advisories
- test-delete-package@99.0.0-dummy
- testatesta@1.0.2
- tdhg-demp@1.0.0
- tailwind-scroller@1.0.2
- tailwindcss-svg-helper@1.17.9
- tailwindcss-framer-motion@1.1.3
- tailwindcss-devtools@1.4.0
- electron-internal-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.