test1gg234@99.99.99
Malicious code in test1gg234 (npm)
T1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The package's preinstall and postinstall hooks both execute index.js, which sends an HTTP request to the hardcoded host 128[.]199[.]122[.]145 with the package name as a query parameter (hxxp://128[.]199[.]122[.]145/?test1gg234). This is an install-time beacon that reports the package name to a remote host on every install.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 08:40 PM
- analyzed
- Sep 18, 2026, 08:41 PM
Related advisories
- test1df23@99.99.99
- test1hh235@99.99.99
- test12vv36@99.99.99
- internallib_v949@1.0.3
- tailwind-form-styles@0.5.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test890-auth@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.