LWA-2026-7228 confirmed malware

test-flow-entire2@1.0.0

Malicious code in test-flow-entire2 (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Package test-flow-entire2@1.0.0 is a stub with no functional code. Its only dependency, marker-hash-macro-daemon, is pinned to a non-registry URL (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/marker-hash-macro-daemon). During npm install, the package manager fetches and installs this dependency from the external host, which serves the actual malicious payload. The package has no repository, no lifecycle scripts, and its index.js exports only static metadata — the sole purpose is to pull in a remote dependency from a non-standard host.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 03:00 PM
analyzed
Jul 29, 2026, 03:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.