zha@0.0.1-security.0
Malicious code in zha (npm)
Analysis
Package zha was published at version 0.0.1-security.0 then immediately removed from the npm registry before its contents could be retrieved for analysis. The version string uses a `.security` prerelease tag, a social-engineering technique designed to trick users and automated dependency managers into treating the package as an official security release. The publish-and-immediately-yank pattern prevents code-level forensic analysis while the package was briefly available for installation. This metadata pattern is consistent with supply-chain attack TTPs including version-squatting and evidence destruction. No code was available for analysis (package unreachable); this advisory is based on metadata alone.
- analyzed by
- Leitwacht
- first seen
- Jun 24, 2026, 01:40 PM
- analyzed
- Jun 24, 2026, 01:41 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.