LWA-2026-7635 confirmed malware
juliusavis@1.0.0
Malicious code in juliusavis (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package is an empty module (index.js exports an empty object) with a French-language casino advertisement README promoting Julius Casino and Spinomenal games. No executable code, no lifecycle hooks, no dependencies. The package is inert casino spam with no detectable malicious behaviour in its current version.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 02:54 PM
- analyzed
- Aug 3, 2026, 02:59 PM
Related advisories
- leon-casino@1.0.1
- simple-date-formatter-util-9@1.0.0
- simple-date-formatter-util-8@1.0.0
- simple-date-formatter-util-7@1.0.0
- europe-fortunecasinofr@1.0.0
- golden-panda-casino@1.0.1
- simple-date-formatter-util-6@1.0.0
- terminal-kit-tslint-config@20.1.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.