LWA-2026-5343 confirmed malware

ttest3333@1.0.0

Malicious code in ttest3333 (npm)

T1195.002 · Compromise Software Supply ChainT1071.001 · Web Protocols

Analysis

Package ttest3333@1.0.0 is a namespace-claim placeholder published by a known repeat-offense malicious actor. The tarball contains only package.json and a PHP/HTML "Coming Soon" page. The package.json references Node.js scripts (src/index.js, test/test.js) that are not present — staging the name for future malicious payload delivery. The shipped index.php includes a browser-side tracking beacon that exfiltrates document.referrer and window.location.href to unpkg[.]com/ttest333@1.0.0/index.php. The package name ttest3333 is a near-typosquat of the beacon target ttest333.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:25 AM
analyzed
Jun 15, 2026, 08:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.