LWA-2026-7625 confirmed malware

staycasinos@1.0.0

Malicious code in staycasinos (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package staycasinos@1.0.0 is an SEO-spam package promoting casino affiliate links. It contains an empty JavaScript stub (module.exports = {}) and a README.md with marketing text and outbound links to staycasino[.]club and staycasino.bet. The package has no lifecycle hooks, no executable code, and no network-exfiltration behaviour — it is an inert placeholder published as part of a known malicious campaign.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 01:54 PM
analyzed
Aug 3, 2026, 01:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.