LWA-2026-7239 MAL-2026-13449 ↗ confirmed malware

merchantweb-lang-cookie-reset@0.0.6

Malicious code in merchantweb-lang-cookie-reset (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

merchantweb-lang-cookie-reset@0.0.6 is a stub package with no functional code (index.js exports only name and version). It declares a single dependency, packet-table-thread-stream, resolved from the non-standard host hxxps://artifacts[.]yosiroute[.]com/npm/packet-table-thread-stream. The shrinkwrap metadata shows that dependency has hasInstallScript: true, meaning it will execute install-time lifecycle hooks fetched from the attacker-controlled server. The package has no repository, no description beyond "Generated package", and exists solely to route npm install to an external registry where the attacker controls the payload.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 02:38 AM
analyzed
Jul 30, 2026, 02:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.