LWA-2026-5762 confirmed malware

srvritto-poquito@1.0.0

Malicious code in srvritto-poquito (npm)

T1059.007 · JavaScriptT1195.002 · Compromise Software Supply Chain

Analysis

srvritto-poquito is a trojanized package that imports a known malicious package (npmkekw) created by the same threat actor and calls its init() function. Installing and requiring this package triggers execution of the attacker's payload from the imported npmkekw module. The malicious behaviour is delivered through the dependency chain, not inlined in the package source.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 09:18 AM
analyzed
Jun 19, 2026, 09:18 AM
weekly installs
567

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.