LWA-2026-3219 MAL-2026-5403 ↗ confirmed malware

t-invest-mcp-server@9999.99.99

Malicious code in t-invest-mcp-server (npm)

Analysis

Package t-invest-mcp-server@9999.99.99 fires high-synthetic-version + high-major-lifecycle-script. Postinstall.js sends an HTTPS POST beacon to ddactic-lab[.]online/sc/beacon with npm_package_{name,version}, process.version, process.platform, CI presence, and GITHUB_REPOSITORY/OWNER/WORKFLOW vars. No credential/token theft (only npm_package_* and CI indicator checks; no NPM_TOKEN/GITHUB_TOKEN/.npmrc/[redacted-marker]). The index.js is a stub that fails back to {}. The package description is cryptic ('npm 404 error referenced in nonnname/t-invest-mcp-server'), repo is under a different GitHub user (Stavmeister vs nonnname), and no README exists — so the flag_benign_research bar (verifiable public research declaration) isn't met. The beacon behavior is real and non-obvious to an installing user, so this warrants human review.

analyzed by
Leitwacht
first seen
Jun 8, 2026, 04:08 PM
analyzed
Jun 8, 2026, 04:10 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.