LWA-2026-5548 confirmed malware
yoshino_s_test_evil@1.0.0
Malicious code in yoshino_s_test_evil (npm)
T1059.007 · JavaScriptT1071 · Application Layer Protocol
Analysis
The package's preinstall hook executes shell.js which establishes a TCP reverse shell to IP 152[.]136[.]32[.]206 on port 6677. It spawns /bin/sh and pipes the shell's stdin/stdout/stderr through the socket, giving the remote attacker interactive shell access on the installer's machine. The main entry point (index.js) is a decoy that prints "Hello, World!".
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 09:27 AM
- analyzed
- Jun 16, 2026, 09:29 AM
Related advisories
- transform-es2015-destructuring@6.24.1
- period-newline@0.1.0
- nodecheck-health@1.0.0
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.