super-test-json@1.2.0
Malicious code in super-test-json (npm)
Analysis
super-test-json@1.2.0 is a trojan disguised as a utility. Its README claims it outputs environment variables as base64-encoded JSON, but the binary entrypoint (bin/cli.js) also recursively renames every .py file found under the current working directory to .py-hacked (rendering them unusable) and executes 'killall python3' to terminate running Python processes. Additionally, the package harvests all environment variables (process.env) and dumps them as base64-encoded output, which can contain API keys, tokens, and credentials. No network exfiltration was observed — the sabotage and credential harvesting are local to the machine where the binary is executed.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 10:18 AM
- analyzed
- Jun 14, 2026, 10:19 AM
Related advisories
- osinthell@1.9.5
- pwdyx@1.0.9
- express-dever@5.1.7
- @web3-helpers/core@1.0.5
- theme-color-picker@2.0.28
- vue-plugin-bomb@1.0.1
- vourfly-tele@4.7.6
- vite-plugin-vue-extend@1.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.