LWA-2026-5305 confirmed malware

tracking-service-config@90.0.0

Malicious code in tracking-service-config (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

tracking-service-config@90.0.0 defines a dependency ("base-package") pointing to an attacker-controlled external HTTP URL (hxxp://npm[.]ezequielpuig[.]space/) rather than the npm registry. When this package is installed, npm resolves the dependency from that external URL, which can serve arbitrary malicious code to the victim's build pipeline. The package ships no actual source code (empty index.js) — its sole function is as a dependency-confusion vector to inject attacker-controlled packages into the install chain via the non-registry dependency specifier. Version 90.0.0 is a version-squat intended to be preferred over legitimate versions.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:33 AM
analyzed
Jun 15, 2026, 05:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.