LWA-2026-5342 confirmed malware
ttest333@1.0.0
Malicious code in ttest333 (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The npm package ttest333@1.0.0 ships no executable code for its target runtime. Its tarball contains only a package.json (with scripts referencing non-existent files src/index.js and test/test.js) and a PHP file (index.php) that is inert in Node.js. This is a placeholder package — the name was registered on the registry without functional code, consistent with a pattern of name reservation intended for a future malicious update.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:25 AM
- analyzed
- Jun 15, 2026, 08:25 AM
Related advisories
- ts-relayer-pub@1.0.0
- tsliverhome@1.1.5
- ts-lint-builds@1.0.5
- ts-lint-builders@1.0.5
- 1edtech_lti_dev@1.2.4
- ts-enum-helper@1.0.0
- txs-data@1.0.1
- trgrip@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.