test1hh235@99.99.99
Malicious code in test1hh235 (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain
Analysis
The package's preinstall and postinstall hooks both execute index.js, which makes an HTTP GET to hxxp://128[.]199[.]122[.]145/?test1hh235, transmitting the package name to a remote host at install time. The package is a 396-byte stub published at synthetic version 99.99.99 with no repository or description, consistent with a dependency-confusion/version-squat beacon.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:40 PM
- analyzed
- Sep 18, 2026, 08:41 PM
Related advisories
- melbet-cm@1.0.0
- tailwind-form-styles@0.5.1
- @shared-web/constants@9.9.9
- @shared-web/modules@9.9.9
- @shared-runtime/api@9.9.9
- @shared-web/tracking@9.9.9
- @shared-web/api@9.9.9
- @shared-runtime/config@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.