LWA-2026-5522 confirmed malware
wp-boilerplate@1.0.1
Malicious code in wp-boilerplate (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
A placeholder package containing only a package.json file with no executable code. The package declares a postinstall hook (node index.js) but ships no index.js — the script will fail with a module-not-found error upon install. This minimal package shape with a lifecycle script and no actual code is characteristic of a namespace-reservation pattern: the package name is claimed in advance for potential later use, often preceding delivery of a malicious payload in a subsequent version.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 05:58 AM
- analyzed
- Jun 16, 2026, 05:59 AM
Related advisories
- work-planner-client@1.0.0
- chai-solidity-testkit@1.6.1
- workbox-stable-xyz@1.0.0
- wordsmith-kit@1.0.0
- wm-idp-sdk@1.2.0
- wisdomtreetest@1.0.1
- winutils-fetch@2.0.0
- winston-prism@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.