LWA-2026-7230 confirmed malware
test-flow-entire4@1.0.0
Malicious code in test-flow-entire4 (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter
Analysis
test-flow-entire4@1.0.0 is a minimal stub package that declares a dependency resolved from a non-registry, attacker-controlled host (hxxps://artifacts[.]stg[.]yosiroute[.]com/npm/source-socket-logger-target). The package itself contains only a trivial index.js exporting name/version with no real functionality. When installed, npm fetches the dependency tarball from the external URL, which can serve arbitrary malicious code that executes during installation or at runtime. The shrinkwrap file pins this external URL as the dependency source.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 04:02 PM
- analyzed
- Jul 29, 2026, 04:03 PM
Related advisories
- voicemail@1.0.1
- fundraiserserv@28.0.0
- @daylightqc/date-fmt-lite@1.1.2
- system-performance-helper@1.0.1
- express-dever@5.1.7
- stellar-api-safe@1.0.8
- chai-foundry@7.0.3
- code-analyzer-mcp@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.