LWA-2026-5762 confirmed malware
srvritto-poquito@1.0.0
Malicious code in srvritto-poquito (npm)
T1059.007 · JavaScriptT1195.002 · Compromise Software Supply Chain
Analysis
srvritto-poquito is a trojanized package that imports a known malicious package (npmkekw) created by the same threat actor and calls its init() function. Installing and requiring this package triggers execution of the attacker's payload from the imported npmkekw module. The malicious behaviour is delivered through the dependency chain, not inlined in the package source.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 09:18 AM
- analyzed
- Jun 19, 2026, 09:18 AM
- weekly installs
- 567
Related advisories
- chai-as-forgeted@9.24.6
- new-helper@5.8.1
- yianzzkf6687@1.0.3
- ts-big-ecro@3.8.1
- stitch-design@0.1.0
- ts-escro@0.0.6
- log-taker@0.0.7
- @xyroorynzz/ocrk@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.