LWA-2026-6117 MAL-2026-6718 ↗ confirmed malware

test-pkg-yarn@1.0.0

Malicious code in test-pkg-yarn (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.003 · Windows Command Shell

Analysis

test-pkg-yarn@1.0.0 shadows the node binary and runs a postinstall hook that executes shim.js. The script prints an educational warning explaining how a yarn postinstall can bypass the package manager's node-bin PATH protection, opens the GitHub research page hxxps://github[.]com/X3r0Day/BunnyHijack in a browser, launches a calculator, and writes a marker file to /tmp/.bun-npm-pwned. It makes no network calls to any remote host, reads no credential files (no .env, ~/.npmrc, ~/.ssh access), and performs no exfiltration of environment variables, tokens, or secrets.

analyzed by
Leitwacht
first seen
Jun 29, 2026, 09:58 AM
analyzed
Jun 29, 2026, 09:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.