LWA-2026-12154 MAL-2026-16217 ↗ confirmed malware

tetotest@14.0.0

Malicious code in tetotest (npm)

T1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1567 · Exfiltration Over Web Service

Analysis

The package contains no application code — only a package.json whose preinstall and postinstall hooks run during installation and POST host metadata to an attacker-controlled Discord webhook (hxxps://discord[.]com/api/webhooks/1413937656697720862/[.][.][.]). The preinstall hook sends the current working directory ($(pwd)); the postinstall hook sends the device hostname ($(hostname)). Installing this package silently reports the installer's host identity to the remote webhook.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 07:52 PM
analyzed
Sep 15, 2026, 07:53 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.