LWA-2026-5266 confirmed malware

testatesta@1.0.2

Malicious code in testatesta (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package testatesta@1.0.2 declares itself as a dependency (circular/self-dependency), making it uninstallable. The package ships a trivial Express server scaffold with no repository, no README, and no legitimate project infrastructure. Its devDependency uses a naming pattern matching the publisher's prior known-malware campaign. The package appears to be a name-reservation stub — reserving the package name on the registry for a future typosquat or dependency confusion attack — rather than a functional module.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 08:18 PM
analyzed
Jun 14, 2026, 08:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.