LWA-2026-7226 confirmed malware

testingflow3@1.0.0

Malicious code in testingflow3 (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

testingflow3@1.0.0 is a dependency-confusion carrier package with no functional code. Its only content is a dependency declaration pointing to an external URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/lookup-codec-locale-atomic) instead of the npm registry. When installed, npm fetches the tarball from this external staging server, which is outside npm's control. The dependency name lookup-codec-locale-atomic mimics a legitimate utility package name. The package has no repository, no lifecycle hooks, and its index.js merely exports a name and version string — the external URL dependency is its sole purpose.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 02:01 PM
analyzed
Jul 29, 2026, 02:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.