tipsen-last@1.0.0
Malicious code in tipsen-last (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
tipsen-last@1.0.0 is a dependency-vector package with no executable code of its own. It declares a dependency on the known-malicious package safe-chain-test, hosted at a Cloudflare tunnel URL (hoped-twice-evaluation-site[.]trycloudflare[.]com) rather than the npm registry. Installing this package would pull in that known-malware payload as a transitive dependency. The package has no repository, no author, and no verifiable provenance for its stated purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 05:52 PM
- analyzed
- Jul 7, 2026, 05:53 PM
Related advisories
- react-next-vite@1.2.9
- mongoose-schema-unique@4.0.4
- motion-pull@2.3.5
- configration@2.3.5
- paperclip-host-utils@1.0.0
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- vps-adapter-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.