LWA-2026-7223 confirmed malware

kyksworldcup4@1.0.0

Malicious code in kyksworldcup4 (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

kyksworldcup4@1.0.0 is a dependency-confusion package that re-exports a dependency from an attacker-controlled external URL. The package's index.js is a single line re-exporting "smart-schema-lib", which is declared as a dependency at hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/smart-schema-lib — an external host outside the npm registry. When a consumer installs and requires this package, npm resolves the dependency from that external URL, giving the host control over what code is served. The package has no lifecycle hooks, no obfuscation, and no repository.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 12:06 PM
analyzed
Jul 29, 2026, 12:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.