LWA-2026-7130 confirmed malware
compress-edge@1.0.0
Malicious code in compress-edge (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
compress-edge@1.0.0 is a metadata-flagged package. The package code is a thin wrapper around the native Compression Streams API (Compressor class with compress/decompress for gzip/deflate/deflate-raw) with no lifecycle hooks, no runtime dependencies, no network calls, and no obfuscation. The finding is based on publisher history rather than malicious code in this version. No IOCs observed in the package contents.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 04:31 PM
- analyzed
- Jul 25, 2026, 04:32 PM
Related advisories
- page-navigation@1.0.1
- xo-member-components@28.0.0
- merchantprefsservice-paypal@28.0.0
- identityauthorizationserv@28.0.0
- fundraiserservpp@1.9.0
- @dhyas23/dicitaz-baileys@1.0.0
- @kite-js-tools/core@1.0.0
- clerk-next-fix-auth-protection@7.7.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.