merchantweb-lang-cookie-reset@0.0.6
Malicious code in merchantweb-lang-cookie-reset (npm)
Analysis
merchantweb-lang-cookie-reset@0.0.6 is a stub package with no functional code (index.js exports only name and version). It declares a single dependency, packet-table-thread-stream, resolved from the non-standard host hxxps://artifacts[.]yosiroute[.]com/npm/packet-table-thread-stream. The shrinkwrap metadata shows that dependency has hasInstallScript: true, meaning it will execute install-time lifecycle hooks fetched from the attacker-controlled server. The package has no repository, no description beyond "Generated package", and exists solely to route npm install to an external registry where the attacker controls the payload.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 02:38 AM
- analyzed
- Jul 30, 2026, 02:38 AM
Related advisories
- rollup-plugins-polyfills-rode@0.13.4
- test-flow-entire5@1.0.0
- express-middle@5.5.1
- test-flow-entire2@1.0.0
- test-flow-entire@1.0.0
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.