LWA-2026-7234 confirmed malware

test-flow-entire5@1.0.0

Malicious code in test-flow-entire5 (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

test-flow-entire5@1.0.0 is a dependency-confusion package that declares its sole dependency as a full HTTPS URL to an attacker-controlled server (artifacts[.]stg[.]yosiroute[.]com) rather than the npm registry. The npm-shrinkwrap.json reveals a full dependency chain — ticket-atomic-memo-plugin, digest-loader-field-schema, and script-token-struct-memo — all resolved from the same external host. The package itself is a trivial stub (73 bytes) whose only function is to pull in this external dependency tree at install time, giving the attacker arbitrary code execution on any system that installs it.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 09:25 PM
analyzed
Jul 29, 2026, 09:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.