LWA-2026-5497 confirmed malware

web-streams-shim@1.0.0

Malicious code in web-streams-shim (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package ships an empty tarball containing only a package.json with no executable code, no README, and no license — a namespace-claim pattern that reserves the package name for a future malicious publish. The name combosquats the legitimate web-streams-polyfill/streams-shim ecosystem. The main field references web-streams-core.js, which does not exist in the package, and there are no lifecycle scripts or executables. The package is a pre-positioning step: the name will likely be updated with a malicious payload in a later version.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 02:58 AM
analyzed
Jun 16, 2026, 02:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.