LWA-2026-5342 confirmed malware

ttest333@1.0.0

Malicious code in ttest333 (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The npm package ttest333@1.0.0 ships no executable code for its target runtime. Its tarball contains only a package.json (with scripts referencing non-existent files src/index.js and test/test.js) and a PHP file (index.php) that is inert in Node.js. This is a placeholder package — the name was registered on the registry without functional code, consistent with a pattern of name reservation intended for a future malicious update.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:25 AM
analyzed
Jun 15, 2026, 08:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.