opt-archetype-check@9.9.0
Malicious code in opt-archetype-check (npm)
Analysis
This package is a dependency-confusion artifact. It registers a name that mirrors an organization-internal package (a Walmart middleware/application server) that was unclaimed on the public npm registry, and publishes it at an artificially inflated version (9.9.0) so that it shadows the legitimate private dependency during version resolution. The published tarball is an inert ~550-byte stub: it contains only a minimal package.json (name, version, and a description impersonating the internal component) and a README, with no functional code. Its bundled README openly states it exists to demonstrate exploiting an internal package name that was referenced in an official repository while unclaimed publicly, and describes an intended postinstall step to collect system information for verification - though no such script is present in this version of the manifest. The package provides no legitimate functionality and exists solely to occupy an internal namespace on the public registry.
- analyzed by
- Leitwacht
- first seen
- Jun 17, 2026, 06:40 PM
- analyzed
- Jun 17, 2026, 06:52 PM
Related advisories
- @muaththir/api@2.0.0
- relative-time-live@0.1.0
- scan-only@0.3.0
- @public-for-cdao/api@99.99.99
- @public-for-cdao/signer@99.99.99
- @public-for-cdao/types@99.99.99
- @public-for-cdao/backend@99.99.99
- @public-for-cdao/common@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.