test-flow-entire@1.0.0
Malicious code in test-flow-entire (npm)
Analysis
test-flow-entire@1.0.0 is a dependency-confusion attack package. The package itself is a trivial stub (72 bytes of JS) with no functionality, but its package.json declares a dependency on "layer-module-kernel-matrix" resolved from the attacker-controlled URL hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/layer-module-kernel-matrix. When npm installs this package, it fetches and installs code from that non-registry URL, which the attacker controls and can serve arbitrary malicious payloads from. The package has no repository, no README of substance, and its sole purpose is to redirect dependency resolution to an external attacker server.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 02:45 PM
- analyzed
- Jul 29, 2026, 02:46 PM
Related advisories
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
- streak-int-lib@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.