LWA-2026-5522 confirmed malware

wp-boilerplate@1.0.1

Malicious code in wp-boilerplate (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

A placeholder package containing only a package.json file with no executable code. The package declares a postinstall hook (node index.js) but ships no index.js — the script will fail with a module-not-found error upon install. This minimal package shape with a lifecycle script and no actual code is characteristic of a namespace-reservation pattern: the package name is claimed in advance for potential later use, often preceding delivery of a malicious payload in a subsequent version.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 05:58 AM
analyzed
Jun 16, 2026, 05:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.