LWA-2026-12261 MAL-2026-16315 ↗ confirmed malware

test1ro@99.99.99

Malicious code in test1ro (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package is a 438-byte stub with no real functionality. Its preinstall and postinstall hooks both run index.js, which reads the machine hostname and sends it over HTTP to the endpoint eo8f3m3ho26a0nm[.]m[.]pipedream[.]net under the path /test1ro?h=<hostname>. Installing the package therefore phones home with the host's identity on every install.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 10:36 PM
analyzed
Sep 18, 2026, 10:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.