LWA-2026-7625 confirmed malware
staycasinos@1.0.0
Malicious code in staycasinos (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package staycasinos@1.0.0 is an SEO-spam package promoting casino affiliate links. It contains an empty JavaScript stub (module.exports = {}) and a README.md with marketing text and outbound links to staycasino[.]club and staycasino.bet. The package has no lifecycle hooks, no executable code, and no network-exfiltration behaviour — it is an inert placeholder published as part of a known malicious campaign.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 01:54 PM
- analyzed
- Aug 3, 2026, 01:55 PM
Related advisories
- sevencasinos@1.0.0
- sportuna@1.0.0
- simple-date-formatter-util-5@1.0.0
- simple-date-formatter-util-4@1.0.0
- a.poltoradnev-package-b@33.9.1
- accounts-limits@0.0.2
- accounts-ddos-shield@33.3.8
- remote_session_elements@9999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.