LWA-2026-7228 confirmed malware
test-flow-entire2@1.0.0
Malicious code in test-flow-entire2 (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Package test-flow-entire2@1.0.0 is a stub with no functional code. Its only dependency, marker-hash-macro-daemon, is pinned to a non-registry URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/marker-hash-macro-daemon). During npm install, the package manager fetches and installs this dependency from the external host, which serves the actual malicious payload. The package has no repository, no lifecycle scripts, and its index.js exports only static metadata — the sole purpose is to pull in a remote dependency from a non-standard host.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 03:00 PM
- analyzed
- Jul 29, 2026, 03:01 PM
Related advisories
- test-flow-entire@1.0.0
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-daykey-lib@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.