LWA-2026-6831 confirmed malware
@npmresearch4/utils@1.0.0
Malicious code in @npmresearch4/utils (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion / combosquat package. The scoped name @npmresearch4/utils mimics an internal npm research utility package. The package is an empty stub (exports an empty object) with no functionality, no repository URL, no documentation, and no lifecycle hooks. It was published solely to squat the name for potential future malicious updates. No executable payload was found in this version.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 09:31 PM
- analyzed
- Jul 15, 2026, 09:31 PM
Related advisories
- @npmresearch4/bench-cbb7@1.0.0
- @npmresearch4/bench-2c83@1.0.0
- ddaxx@1.0.0
- api-rs-tuils@2.1.6
- xxdxax@1.0.1
- axios-test-one@1.19.0
- telemetry-metrics@0.2.1
- @mp-op-ss-front-lib/tracks@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.