LWA-2026-5230 confirmed malware

super-test-json@1.2.0

Malicious code in super-test-json (npm)

T1485 · Data DestructionT1489 · Service StopT1552.001 · Credentials In FilesT1082 · System Information Discovery

Analysis

super-test-json@1.2.0 is a trojan disguised as a utility. Its README claims it outputs environment variables as base64-encoded JSON, but the binary entrypoint (bin/cli.js) also recursively renames every .py file found under the current working directory to .py-hacked (rendering them unusable) and executes 'killall python3' to terminate running Python processes. Additionally, the package harvests all environment variables (process.env) and dumps them as base64-encoded output, which can contain API keys, tokens, and credentials. No network exfiltration was observed — the sabotage and credential harvesting are local to the machine where the binary is executed.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 10:18 AM
analyzed
Jun 14, 2026, 10:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.