test-pkg-yarn@1.0.0
Malicious code in test-pkg-yarn (npm)
Analysis
test-pkg-yarn@1.0.0 shadows the node binary and runs a postinstall hook that executes shim.js. The script prints an educational warning explaining how a yarn postinstall can bypass the package manager's node-bin PATH protection, opens the GitHub research page hxxps://github[.]com/X3r0Day/BunnyHijack in a browser, launches a calculator, and writes a marker file to /tmp/.bun-npm-pwned. It makes no network calls to any remote host, reads no credential files (no .env, ~/.npmrc, ~/.ssh access), and performs no exfiltration of environment variables, tokens, or secrets.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 09:58 AM
- analyzed
- Jun 29, 2026, 09:59 AM
Related advisories
- openllmapi@4.0.2
- easyllmai@3.0.1
- toast-react-slider@1.0.0
- textify-kit@1.0.0
- stringsculpt-kit@1.0.0
- optional-cpu-features@1.0.3
- @ethers-js/contracts@6.9.0
- sme-rko-finance-front-operations-domain@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.