LWA-2026-5376 confirmed malware
u-paging@0.0.0
Malicious code in u-paging (npm)
T1195.002 · Compromise Software Supply ChainT1656 · Impersonation
Analysis
Namespace-squatting package u-paging@0.0.0 contains no executable code — only an empty shell package.json, README, and LICENSE. The package impersonates the well-known open-source developer Anthony Fu (antfu) in its author field, homepage, and README template, but is published by a different actor. This is a pre-positioning step: reserving the package name under a falsely claimed identity to later ship a malicious version that would auto-update for existing installs.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 12:31 PM
- analyzed
- Jun 15, 2026, 12:32 PM
Related advisories
- vitest-pro@7.0.4
- unico-check@9.9.9
- unicocheck-ios@9.9.9
- unico-android@9.9.9
- cardano-addresses-docs@1.0.1
- unicode-colors@4.1.4
- ultra-base64-math@1.0.2
- umi-preset-rce-jytest@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.