LWA-2026-4230 MAL-2026-5645 ↗ confirmed malware

sn-internal-test@1.9.9

Malicious code in sn-internal-test (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1195.002 · Compromise Software Supply Chain

Analysis

Package sn-internal-test@1.9.9 has a preinstall script that curls hxxps://poc[.]amanrawat[.]com/hehe[.]js and executes it with node — remote code execution on install. The host poc[.]amanrawat[.]com is not on the allowlist of legitimate installer hosts (deno.land, bun.sh, rustup.rs, etc.). The package is a single-version (1.9. No token-theft markers were found in the package, but the preinstall download-and-execute pattern with a non-allowlisted C2 host is unambiguous malware intent: the remote payload can be swapped at any time.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:32 AM
analyzed
Jun 11, 2026, 11:32 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.