LWA-2026-7623 confirmed malware
sevencasinos@1.0.0
Malicious code in sevencasinos (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package exports an empty object (module.exports = {}) and contains no executable code, no lifecycle hooks, and no dependencies. The only substantive content is a README with promotional text and affiliate links for a casino website (sevencasinos[.]net). No network IOCs, no credential theft, and no runtime payload were observed.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 01:54 PM
- analyzed
- Aug 3, 2026, 01:55 PM
Related advisories
- sportuna@1.0.0
- simple-date-formatter-util-5@1.0.0
- simple-date-formatter-util-4@1.0.0
- a.poltoradnev-package-b@33.9.1
- accounts-limits@0.0.2
- accounts-ddos-shield@33.3.8
- remote_session_elements@9999.0.0
- dc-renewals-layout2@9999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.