LWA-2026-7225 confirmed malware
testingflow2@1.0.0
Malicious code in testingflow2 (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
testingflow2@1.0.0 is a dependency-substitution package. It declares a dependency on "fast-utils-core" resolved from the attacker-controlled URL hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/fast-utils-core instead of the public npm registry. When installed, npm fetches the dependency from this external server, giving the attacker arbitrary code execution in the installer's context. The package itself is a trivial stub with no functional code; its sole purpose is to hijack the dependency resolution.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 01:58 PM
- analyzed
- Jul 29, 2026, 01:59 PM
Related advisories
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
- utils-style-engine@10.2.4
- dilxztech@1.0.0
- po-ops-local-dev@99.9.1
- webrix-docs1@10.2.11
- lusha-iam-widgets@1.5.2
- driftpin@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.