OpenSSF/OSV advisory MAL-2026-4624 confirms this npm version as malicious. Package is published publicly on npm at version 100.20.33 — a version-number shape used in dependency-confusion attacks to outrank private internal packages of the same name. The package.json claims authorship by 'Atlassian Ecosystem Engineering' and describes itself as an 'Atlassian internal demonstration and utility framework', but the package is published to the public registry under no Atlassian-owned scope...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in nw-demo (npm)
Details
Package is published publicly on npm at version 100.20.33 — a version-number shape used in dependency-confusion attacks to outrank private internal packages of the same name. The package.json claims authorship by 'Atlassian Ecosystem Engineering' and describes itself as an 'Atlassian internal demonstration and utility framework', but the package is published to the public registry under no Atlassian-owned scope. The main entry index.js contains only `try { require('nw-demo-utils'); } catch (e) { }` — its sole behavior on import is to silently load and execute a separately-published transitive dependency (`nw-demo-utils ^1.0.16`), with errors swallowed to hide failures. The README instructs consumers to `require('nw-demo')`, which transitively executes nw-demo-utils' module-load code in the installer's process. The wrapper itself ships no payload; it functions as a loader that laundries arbitrary code from nw-demo-utils into any pipeline that mistakenly resolves the public package over a private internal one.
Decision reason
OpenSSF Malicious Packages via OSV confirms nw-demo@100.20.33 as malicious (MAL-2026-4624): Malicious code in nw-demo (npm)