Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)

Malicious code was published in the npm package "-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home". The package was identified and cataloged by the OpenSSF malicious packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; package name suggests limited legitimate use
Ecosystems
Attack vectors
Affected entities
  • -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-homenpm package

A malicious npm package named "-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home" was identified and reported. The package contained malicious code and was documented in the OpenSSF's malicious packages repository (MAL-2024-1695).\n\nThe package name suggests it was designed to deceive users searching for movie-related content, a common typosquatting or social engineering tactic. The incident was disclosed on 2026-07-25 via GitHub Security Advisory GHSA-278x-2crc-394c.\n\nNo specific technical details about the malicious payload or affected versions are provided in the source material.

Indicators of compromise

Packages
  • -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home

Remediation

  • Remove the package from any environments where it may have been installed
  • Audit npm dependencies for this package name and similar typosquatting variants
  • Review the OpenSSF malicious packages database for additional context and indicators
  • Implement package name validation and allowlisting policies in dependency management

Sources

  1. GitHub Advisory GHSA-278x-2crc-394c · GitHub Advisory Database

Cite this entry

"Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 25, 2026; last updated July 25, 2026. https://supplychainattack.org/incident/malicious-code-in-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-1hn309

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  2. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  3. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  4. containedcritical

    Malicious code in -pem-misa (npm)

    The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit