LWA-2026-12718 confirmed malware

@wxwxtest/testrrrdd@1.0.0

Malicious code in @wxwxtest/testrrrdd (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

@wxwxtest/testrrrdd ships a postinstall hook ("postinstall": "node beacon.cjs") that runs on every install and silently POSTs host metadata to a hardcoded remote endpoint. beacon.cjs collects the package name, the machine hostname (os.hostname()), the install directory (__dirname), the current working directory, and the Node/npm version, then sends them as JSON to hxxp://185[.]158[.]107[.]175:8787/_ah/dc with an "x-beacon-package" header. The request is fire-and-forget: errors and timeouts are swallowed so the install appears to succeed normally, and the package's index.js is an empty compatibility shim, so nothing in the package's visible behaviour hints at the outbound call. The same beacon is present in versions 0.0.1, 1.0.0, 2.0.1 and 3.0.0. The package name is a combosquat of the real "testrrrd" package, and the README's claim that this is an "authorized dependency-confusion test" is an unverifiable self-assertion that does not change the behaviour: installing the package leaks the installer's hostname and filesystem paths to a third-party IP. IOCs: C2 host 185[.]158[.]107[.]175:8787, POST path /_ah/dc.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 07:18 PM
analyzed
Oct 8, 2026, 07:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.