testingflow3@1.0.0
Malicious code in testingflow3 (npm)
Analysis
testingflow3@1.0.0 is a dependency-confusion carrier package with no functional code. Its only content is a dependency declaration pointing to an external URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/lookup-codec-locale-atomic) instead of the npm registry. When installed, npm fetches the tarball from this external staging server, which is outside npm's control. The dependency name lookup-codec-locale-atomic mimics a legitimate utility package name. The package has no repository, no lifecycle hooks, and its index.js merely exports a name and version string — the external URL dependency is its sole purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 02:01 PM
- analyzed
- Jul 29, 2026, 02:02 PM
Related advisories
- testingflow2@1.0.0
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
- chai-as-map@2.3.5
- streak-grid-core@1.0.0
- test22221@2.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.