LWA-2026-7229 confirmed malware

test-flow-entire3@1.0.0

Malicious code in test-flow-entire3 (npm)

T1195.002 · Compromise Software Supply ChainT1195 · Supply Chain Compromise

Analysis

Package test-flow-entire3@1.0.0 is a dependency-confusion carrier. It declares a dependency ("writer-field-reader-router") as a full HTTPS URL pointing to artifacts[.]stg[.]yosiroute[.]com/npm/writer-field-reader-router — a non-registry host. When installed, npm fetches the dependency tarball from this attacker-controlled server, allowing arbitrary code execution at install time. The package itself is a stub with no functional code.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 03:07 PM
analyzed
Jul 29, 2026, 03:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.