LWA-2026-7229 confirmed malware
test-flow-entire3@1.0.0
Malicious code in test-flow-entire3 (npm)
T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise
Analysis
Package test-flow-entire3@1.0.0 is a dependency-confusion carrier. It declares a dependency ("writer-field-reader-router") as a full HTTPS URL pointing to artifacts[.]stg[.]yosiroute[.]com/npm/writer-field-reader-router — a non-registry host. When installed, npm fetches the dependency tarball from this attacker-controlled server, allowing arbitrary code execution at install time. The package itself is a stub with no functional code.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 03:07 PM
- analyzed
- Jul 29, 2026, 03:07 PM
Related advisories
- testingflow2@1.0.0
- @queenanya/baileys@9.7.1
- @cr-invested-ui-components/chart@99.9.1
- utils-style-engine@10.2.4
- dilxztech@1.0.0
- po-ops-local-dev@99.9.1
- webrix-docs1@10.2.11
- lusha-iam-widgets@1.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.