LWA-2026-7238 confirmed malware
commonweb-flow@1.0.0
Malicious code in commonweb-flow (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter
Analysis
Package commonweb-flow@1.0.0 is a minimal stub (exports name/version only) that declares a dependency on linker-event-header-serial resolved from hxxps://artifacts[.]yosiroute[.]com/npm/linker-event-header-serial — a non-registry, non-standard host. The npm-shrinkwrap.json confirms the remote dependency has an install script (hasInstallScript: true), enabling arbitrary code execution at install time. The package has no repository, no meaningful documentation, and its sole function is to pull a remote tarball from an external host outside the npm registry.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 02:36 AM
- analyzed
- Jul 30, 2026, 02:37 AM
Related advisories
- test-flow-entire4@1.0.0
- voicemail@1.0.1
- fundraiserserv@28.0.0
- @daylightqc/date-fmt-lite@1.1.2
- system-performance-helper@1.0.1
- express-dever@5.1.7
- stellar-api-safe@1.0.8
- chai-foundry@7.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.