LWA-2026-7648 confirmed malware
wildsinos@1.0.1
Malicious code in wildsinos (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package ships an empty module (module.exports = {}) with no functional code, no lifecycle hooks, no scripts, and no dependencies. Its only content is a German-language README promoting a casino affiliate site (wildsinos.at). The package has no executable payload but is published by an account that has exclusively published malware across multiple prior packages.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 03:39 PM
- analyzed
- Aug 3, 2026, 03:41 PM
Related advisories
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-12@1.0.0
- simple-date-formatter-util-10@1.0.0
- shuffle-casinos@1.0.0
- robocatenligne@1.0.1
- rizzcasinofrance@1.0.0
- kinbetfrcasino@1.0.0
- juliusavis@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.