sn-internal-test@1.9.9
Malicious code in sn-internal-test (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1195.002 · Compromise Software Supply Chain
Analysis
Package sn-internal-test@1.9.9 has a preinstall script that curls hxxps://poc[.]amanrawat[.]com/hehe[.]js and executes it with node — remote code execution on install. The host poc[.]amanrawat[.]com is not on the allowlist of legitimate installer hosts (deno.land, bun.sh, rustup.rs, etc.). The package is a single-version (1.9. No token-theft markers were found in the package, but the preinstall download-and-execute pattern with a non-allowlisted C2 host is unambiguous malware intent: the remote payload can be swapped at any time.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:32 AM
- analyzed
- Jun 11, 2026, 11:32 AM
Related advisories
- nodecheck-health@1.0.0
- self-certificate@1.0.0
- nj-logger@1.3.2
- reading-cookies@6.13.2
- niieani@7.9.0
- ng-search-api@99.9.1
- ts-ecro@0.0.6
- parket-slot@0.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.