LWA-2026-7240 MAL-2026-13371 ↗ confirmed malware

multi-acct@1.0.0

Malicious code in multi-acct (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

multi-acct@1.0.0 is a dependency-confusion package that pins its sole dependency (vector-cursor-stream-engine) to a non-registry URL at artifacts[.]yosiroute[.]com. The npm-shrinkwrap.json confirms the remote dependency has an install script (hasInstallScript: true), meaning npm will fetch and execute arbitrary code from the attacker-controlled server at install time. The package itself is a trivial wrapper with no functional code. IOC: hxxps://artifacts[.]yosiroute[.]com/npm/vector-cursor-stream-engine, domain: artifacts[.]yosiroute[.]com.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 02:40 AM
analyzed
Jul 30, 2026, 02:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.