LWA-2026-6035 confirmed malware
zhuanhua@1.1.99
Malicious code in zhuanhua (npm)
T1195.002 · Compromise Software Supply ChainT1496 · Resource Hijacking
Analysis
zhuanhua@1.1.99 is a dependency-confusion stub (version-squatted to 1.1.99, copied README from another package) that ships a malicious browser iframe-injection script in px.js alongside a legitimate Simplified↔Traditional Chinese converter. The px.js script creates a fullscreen loading overlay and redirects the viewer via an iframe to hxxps://tckyv[.]ygh8tas[.]icu, a non-allowlisted external domain. The script is inactive at install time (no lifecycle hooks) but is bundled as part of the package and would execute if imported in a browser context.
- analyzed by
- Leitwacht
- first seen
- Jun 27, 2026, 02:48 AM
- analyzed
- Jun 27, 2026, 02:49 AM
- weekly installs
- 7,862
Related advisories
- @dilxzphrine/baileys@1.0.0
- xeiko-cdn@1.0.0
- mev-shield@1.4.2
- fb-cards-form-no-resident-information@20.4.4
- crypto-base58@1.0.1
- chai-as-persisted@4.2.8
- react-dynammic-table-component@1.2.7
- react-dynamic-table-compenent@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.