ttest3333@1.0.0
Malicious code in ttest3333 (npm)
Analysis
Package ttest3333@1.0.0 is a namespace-claim placeholder published by a known repeat-offense malicious actor. The tarball contains only package.json and a PHP/HTML "Coming Soon" page. The package.json references Node.js scripts (src/index.js, test/test.js) that are not present — staging the name for future malicious payload delivery. The shipped index.php includes a browser-side tracking beacon that exfiltrates document.referrer and window.location.href to unpkg[.]com/ttest333@1.0.0/index.php. The package name ttest3333 is a near-typosquat of the beacon target ttest333.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:25 AM
- analyzed
- Jun 15, 2026, 08:26 AM
Related advisories
- ttest333@1.0.0
- ts-relayer-pub@1.0.0
- tsliverhome@1.1.5
- ts-lint-builds@1.0.5
- ts-lint-builders@1.0.5
- 1edtech_lti_dev@1.2.4
- ts-enum-helper@1.0.0
- txs-data@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.