LWA-2026-7223 confirmed malware
kyksworldcup4@1.0.0
Malicious code in kyksworldcup4 (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
kyksworldcup4@1.0.0 is a dependency-confusion package that re-exports a dependency from an attacker-controlled external URL. The package's index.js is a single line re-exporting "smart-schema-lib", which is declared as a dependency at hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/smart-schema-lib — an external host outside the npm registry. When a consumer installs and requires this package, npm resolves the dependency from that external URL, giving the host control over what code is served. The package has no lifecycle hooks, no obfuscation, and no repository.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 12:06 PM
- analyzed
- Jul 29, 2026, 12:08 PM
Related advisories
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
- test22221@2.2.7
- nagixjs@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.