test1ro@99.99.99
Malicious code in test1ro (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package is a 438-byte stub with no real functionality. Its preinstall and postinstall hooks both run index.js, which reads the machine hostname and sends it over HTTP to the endpoint eo8f3m3ho26a0nm[.]m[.]pipedream[.]net under the path /test1ro?h=<hostname>. Installing the package therefore phones home with the host's identity on every install.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 10:36 PM
- analyzed
- Sep 18, 2026, 10:37 PM
Related advisories
- bulk-add-sdk@1.99.99
- test8999-auth@1.0.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test899-auth@1.0.1
- test89-auth@1.0.1
- test890-auth@1.0.0
- montreal-core@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.