testssdd@1.0.0
Malicious code in testssdd (npm)
Analysis
Package ships a C2 bot configuration under the deceptive filename 'fontlist' (not a font list). The JSON contains 5 C2 host URLs (u2[.]ed45fgb455[.]store:http, u2[.]d4456xsg4434[.]online:https, u2[.]nb65y56fgd[.]space:http, u2[.]kcjlkv4509jfdg[.]xyz:http, u2[.]flkasxd439gf[.]online:http), a report endpoint at /cpc/api/report, a task endpoint at /cpc/api/task, 5 update server URLs (b2[.]ed45fgb455[.]store, b1[.]vrr8345[.]site, b2[.]nb65y56fgd[.]space, b2[.]kcjlkv4509jfdg[.]xyz, b2[.]flkasxd439gf[.]online), a config version, and a polling interval of 2,700,000ms (45 minutes). The package.json 'main' field points to this configuration file, so requiring the package returns the C2 infrastructure details — intended as a configuration seed for a botnet payload.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 10:17 PM
- analyzed
- Jun 14, 2026, 10:18 PM
Related advisories
- tailwind-scroller@1.0.2
- tailwindcss-svg-helper@1.17.9
- tailwindcss-framer-motion@1.1.3
- tailwindcss-devtools@1.4.0
- tailwindcss-animate-builder@2.1.0
- tailmagic@2.3.2
- tabbables@45.0.0
- system-driver@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.