LWA-2026-5599 MAL-2026-5918 ↗ confirmed malware

nottuff7@1.7.7

Malicious code in nottuff7 (npm)

T1027 · Obfuscated Files or Information

Analysis

This package is one of roughly ninety-five coordinated, mass-published npm names that all ship the same browser-based web-proxy payload as a static site, abusing public npm CDNs (unpkg/jsdelivr) as the delivery channel so users can reach a web-filter-bypass proxy through registry-CDN hostnames rather than via npm install. The declared entry point is a browser ServiceWorker (sw.js) with no Node lifecycle hooks, so installing or requiring the package executes nothing on a developer machine; the malicious behaviour runs only when the bundled assets are loaded in a browser. The ServiceWorker injects a script into proxied pages that forces new-tab navigations, and the cover page (a decoy tutoring landing page) runs inline code that, on the first user click, keypress, or touch, opens a pop-under window to an external ad URL (hxxps://abdct[.]com/) gated by a fifteen-minute localStorage cooldown, and additionally loads a remote third-party script. The package also bundles a shell script (auto-publish.sh) that iterates a hardcoded list of package names and force-publishes each to npm, documenting the deliberate registry-pollution / ad-monetization intent.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 08:19 PM
analyzed
Jun 16, 2026, 08:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.