LWA-2026-5273 confirmed malware

testssdd@1.0.0

Malicious code in testssdd (npm)

T1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Package ships a C2 bot configuration under the deceptive filename 'fontlist' (not a font list). The JSON contains 5 C2 host URLs (u2[.]ed45fgb455[.]store:http, u2[.]d4456xsg4434[.]online:https, u2[.]nb65y56fgd[.]space:http, u2[.]kcjlkv4509jfdg[.]xyz:http, u2[.]flkasxd439gf[.]online:http), a report endpoint at /cpc/api/report, a task endpoint at /cpc/api/task, 5 update server URLs (b2[.]ed45fgb455[.]store, b1[.]vrr8345[.]site, b2[.]nb65y56fgd[.]space, b2[.]kcjlkv4509jfdg[.]xyz, b2[.]flkasxd439gf[.]online), a config version, and a polling interval of 2,700,000ms (45 minutes). The package.json 'main' field points to this configuration file, so requiring the package returns the C2 infrastructure details — intended as a configuration seed for a botnet payload.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 10:17 PM
analyzed
Jun 14, 2026, 10:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.