merchantweb-lang-cookie-reset@0.0.6
Malicious code in merchantweb-lang-cookie-reset (npm)
Analysis
merchantweb-lang-cookie-reset@0.0.6 is a stub package with no functional code (index.js exports only name and version). It declares a single dependency, packet-table-thread-stream, resolved from the non-standard host hxxps://artifacts[.]yosiroute[.]com/npm/packet-table-thread-stream. The shrinkwrap metadata shows that dependency has hasInstallScript: true, meaning it will execute install-time lifecycle hooks fetched from the attacker-controlled server. The package has no repository, no description beyond "Generated package", and exists solely to route npm install to an external registry where the attacker controls the payload.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 02:38 AM
- analyzed
- Jul 30, 2026, 02:38 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.