LWA-2026-6035 confirmed malware

zhuanhua@1.1.99

Malicious code in zhuanhua (npm)

T1195.002 · Compromise Software Supply ChainT1496 · Resource Hijacking

Analysis

zhuanhua@1.1.99 is a dependency-confusion stub (version-squatted to 1.1.99, copied README from another package) that ships a malicious browser iframe-injection script in px.js alongside a legitimate Simplified↔Traditional Chinese converter. The px.js script creates a fullscreen loading overlay and redirects the viewer via an iframe to hxxps://tckyv[.]ygh8tas[.]icu, a non-allowlisted external domain. The script is inactive at install time (no lifecycle hooks) but is bundled as part of the package and would execute if imported in a browser context.

analyzed by
Leitwacht
first seen
Jun 27, 2026, 02:48 AM
analyzed
Jun 27, 2026, 02:49 AM
weekly installs
7,862

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.