LWA-2026-7224 confirmed malware
testingnewflow@1.0.0
Malicious code in testingnewflow (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
testingnewflow@1.0.0 is a stub package (70 bytes, no real code) that declares a dependency safe-buffer-helper pinned to a non-registry URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/safe-buffer-helper). When installed, npm fetches this dependency from the attacker-controlled host, giving the attacker arbitrary code execution on the installer's machine. The package has no repository, no README content of substance, and no legitimate functionality — it exists solely as a dependency-confusion vector to pull remote code.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 01:44 PM
- analyzed
- Jul 29, 2026, 01:44 PM
Related advisories
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
- test22221@2.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.