test12vv36@99.99.99
Malicious code in test12vv36 (npm)
T1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
A 396-byte package with no real functionality, published at version 99.99.99. Both its preinstall and postinstall hooks execute `node index.js --save-prod`, which makes an HTTP GET request to hxxp://128[.]199[.]122[.]145/?test12vv36 on install, beaconing the package name to a remote IP address. The package exists solely to report installs to this host.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:39 PM
- analyzed
- Sep 18, 2026, 08:40 PM
Related advisories
- internallib_v949@1.0.3
- tailwind-form-styles@0.5.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test890-auth@1.0.0
- montreal-core@0.1.0
- catwrestlingbird@1.0.0
- homestack-cheer@1.1.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.