test-flow-entire5@1.0.0
Malicious code in test-flow-entire5 (npm)
Analysis
test-flow-entire5@1.0.0 is a dependency-confusion package that declares its sole dependency as a full HTTPS URL to an attacker-controlled server (artifacts[.]stg[.]yosiroute[.]com) rather than the npm registry. The npm-shrinkwrap.json reveals a full dependency chain — ticket-atomic-memo-plugin, digest-loader-field-schema, and script-token-struct-memo — all resolved from the same external host. The package itself is a trivial stub (73 bytes) whose only function is to pull in this external dependency tree at install time, giving the attacker arbitrary code execution on any system that installs it.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 09:25 PM
- analyzed
- Jul 29, 2026, 09:26 PM
Related advisories
- express-middle@5.5.1
- test-flow-entire2@1.0.0
- test-flow-entire@1.0.0
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
- streak-view-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.