test1df23@99.99.99
Malicious code in test1df23 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The package declares a high version (99.99.99) on a new name and runs a lifecycle hook on install. Both the preinstall and postinstall hooks execute index.js, which requires the typosquat dependency `requests` and sends an HTTP GET to hxxp://128[.]199[.]122[.]145/?test1df23, beaconing the package name to a hardcoded remote host at install time.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:40 PM
- analyzed
- Sep 18, 2026, 08:41 PM
Related advisories
- test1hh235@99.99.99
- melbet-cm@1.0.0
- tailwind-form-styles@0.5.1
- @shared-web/constants@9.9.9
- @shared-web/modules@9.9.9
- @shared-runtime/api@9.9.9
- @shared-web/tracking@9.9.9
- @shared-web/api@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.