multi-acct@1.0.0
Malicious code in multi-acct (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
multi-acct@1.0.0 is a dependency-confusion package that pins its sole dependency (vector-cursor-stream-engine) to a non-registry URL at artifacts[.]yosiroute[.]com. The npm-shrinkwrap.json confirms the remote dependency has an install script (hasInstallScript: true), meaning npm will fetch and execute arbitrary code from the attacker-controlled server at install time. The package itself is a trivial wrapper with no functional code. IOC: hxxps://artifacts[.]yosiroute[.]com/npm/vector-cursor-stream-engine, domain: artifacts[.]yosiroute[.]com.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 02:40 AM
- analyzed
- Jul 30, 2026, 02:40 AM
Related advisories
- merchantweb-lang-cookie-reset@0.0.6
- rollup-plugins-polyfills-rode@0.13.4
- test-flow-entire5@1.0.0
- express-middle@5.5.1
- test-flow-entire2@1.0.0
- test-flow-entire@1.0.0
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.