LWA-2026-7230 confirmed malware

test-flow-entire4@1.0.0

Malicious code in test-flow-entire4 (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter

Analysis

test-flow-entire4@1.0.0 is a minimal stub package that declares a dependency resolved from a non-registry, attacker-controlled host (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/source-socket-logger-target). The package itself contains only a trivial index.js exporting name/version with no real functionality. When installed, npm fetches the dependency tarball from the external URL, which can serve arbitrary malicious code that executes during installation or at runtime. The shrinkwrap file pins this external URL as the dependency source.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 04:02 PM
analyzed
Jul 29, 2026, 04:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.