LWA-2026-5497 confirmed malware
web-streams-shim@1.0.0
Malicious code in web-streams-shim (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package ships an empty tarball containing only a package.json with no executable code, no README, and no license — a namespace-claim pattern that reserves the package name for a future malicious publish. The name combosquats the legitimate web-streams-polyfill/streams-shim ecosystem. The main field references web-streams-core.js, which does not exist in the package, and there are no lifecycle scripts or executables. The package is a pre-positioning step: the name will likely be updated with a malicious payload in a later version.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 02:58 AM
- analyzed
- Jun 16, 2026, 02:59 AM
Related advisories
- pretie_x1@3.8.5
- wordpad-text-ui@1.0.0
- check-ulid@3.0.2
- webpack-cdn-fetcher@1.0.1
- web3-core-utils@4.3.5
- weavedb-node-client@0.45.3
- walletconnectionjs@1.1.1
- wac-atl-context@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.