testingsmthb1g@1.0.0
Malicious code in testingsmthb1g (npm)
Analysis
The postinstall hook (scripts/postinstall.js) runs on install. It POSTs an install beacon (node version, arch, platform) to 193[.]70[.]34[.]101:20099/vote. On Windows and WSL hosts it downloads a Windows executable main.exe from hxxps://github[.]com/beebraz1/qPzM50V1AKG0rVlH/release/download/null/main[.]exe into %TEMP%\main.exe and executes it — on native Windows via a detached spawn, on WSL via a hidden PowerShell command (powershell.exe -WindowStyle Hidden -NoProfile -NonInteractive -ExecutionPolicy Bypass) that runs Invoke-WebRequest to fetch and run the binary. The download URL and C2 host are XOR-obfuscated in the script.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 02:28 AM
- analyzed
- Aug 16, 2026, 02:29 AM
Related advisories
- @biklitime/biklimaster@1.1.6
- @rblxts/services@1.6.0
- @solana-js/web3@1.91.3
- @coralxyz/anchor@0.30.2
- @rbx-ts/services@1.6.0
- wormgpt-cli@1.0.1
- dolyame-ui-swiper@35.7.7
- stellarfixer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.