LWA-2026-12254 MAL-2026-16312 ↗ confirmed malware

test1df23@99.99.99

Malicious code in test1df23 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package declares a high version (99.99.99) on a new name and runs a lifecycle hook on install. Both the preinstall and postinstall hooks execute index.js, which requires the typosquat dependency `requests` and sends an HTTP GET to hxxp://128[.]199[.]122[.]145/?test1df23, beaconing the package name to a hardcoded remote host at install time.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 08:40 PM
analyzed
Sep 18, 2026, 08:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.