LWA-2026-7225 confirmed malware

testingflow2@1.0.0

Malicious code in testingflow2 (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

testingflow2@1.0.0 is a dependency-substitution package. It declares a dependency on "fast-utils-core" resolved from the attacker-controlled URL hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/fast-utils-core instead of the public npm registry. When installed, npm fetches the dependency from this external server, giving the attacker arbitrary code execution in the installer's context. The package itself is a trivial stub with no functional code; its sole purpose is to hijack the dependency resolution.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 01:58 PM
analyzed
Jul 29, 2026, 01:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.