LWA-2026-5548 confirmed malware

yoshino_s_test_evil@1.0.0

Malicious code in yoshino_s_test_evil (npm)

T1059.007 · JavaScriptT1071 · Application Layer Protocol

Analysis

The package's preinstall hook executes shell.js which establishes a TCP reverse shell to IP 152[.]136[.]32[.]206 on port 6677. It spawns /bin/sh and pipes the shell's stdin/stdout/stderr through the socket, giving the remote attacker interactive shell access on the installer's machine. The main entry point (index.js) is a decoy that prints "Hello, World!".

analyzed by
Leitwacht
first seen
Jun 16, 2026, 09:27 AM
analyzed
Jun 16, 2026, 09:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.