LWA-2026-12256 MAL-2026-16313 ↗ confirmed malware

test1gg234@99.99.99

Malicious code in test1gg234 (npm)

T1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package's preinstall and postinstall hooks both execute index.js, which sends an HTTP request to the hardcoded host 128[.]199[.]122[.]145 with the package name as a query parameter (hxxp://128[.]199[.]122[.]145/?test1gg234). This is an install-time beacon that reports the package name to a remote host on every install.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 08:40 PM
analyzed
Sep 18, 2026, 08:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.