LWA-2026-7238 confirmed malware

commonweb-flow@1.0.0

Malicious code in commonweb-flow (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter

Analysis

Package commonweb-flow@1.0.0 is a minimal stub (exports name/version only) that declares a dependency on linker-event-header-serial resolved from hxxps://artifacts[.]yosiroute[.]com/npm/linker-event-header-serial — a non-registry, non-standard host. The npm-shrinkwrap.json confirms the remote dependency has an install script (hasInstallScript: true), enabling arbitrary code execution at install time. The package has no repository, no meaningful documentation, and its sole function is to pull a remote tarball from an external host outside the npm registry.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 02:36 AM
analyzed
Jul 30, 2026, 02:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.