LWA-2026-6477 MAL-2026-6075 ↗ confirmed malware

opt-archetype-check@9.9.0

Malicious code in opt-archetype-check (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This package is a dependency-confusion artifact. It registers a name that mirrors an organization-internal package (a Walmart middleware/application server) that was unclaimed on the public npm registry, and publishes it at an artificially inflated version (9.9.0) so that it shadows the legitimate private dependency during version resolution. The published tarball is an inert ~550-byte stub: it contains only a minimal package.json (name, version, and a description impersonating the internal component) and a README, with no functional code. Its bundled README openly states it exists to demonstrate exploiting an internal package name that was referenced in an official repository while unclaimed publicly, and describes an intended postinstall step to collect system information for verification - though no such script is present in this version of the manifest. The package provides no legitimate functionality and exists solely to occupy an internal namespace on the public registry.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 06:40 PM
analyzed
Jun 17, 2026, 06:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.