LWA-2026-5270 confirmed malware

test-multi-versions@1.0.0

Malicious code in test-multi-versions (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Metadata-only finding: the package contains only a package.json file with no executable code, no lifecycle scripts, and no binary entries. The package name suggests a test/namespace-reservation pattern. No network IOCs, no exfiltration behavior, and no malicious code are present in this version. The significance is that the package is an empty stub published under a name that appears to be a namespace reservation, with no other observable behavior to describe at this version.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 09:32 PM
analyzed
Jun 14, 2026, 09:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.