LWA-2026-6262 confirmed malware

webrix-docs@19.2.11

Malicious code in webrix-docs (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

webrix-docs is a typosquat of the legitimate webix-docs documentation package. The package has no repository, no description, and a high version number (19.2.11) on its first and only publication. It installs a preinstall hook that runs node index.js on install, automatically executing the package's main entry point without the installer's knowledge or consent. The package was published under a name that differs from the real webix-docs by one character (webrix vs webix), intended to catch typo-prone installs and run code on the victim's machine during npm install.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 03:44 PM
analyzed
Jul 2, 2026, 03:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.