LWA-2026-6212 MAL-2026-6710 ↗ confirmed malware

vitest-agent@1.0.5

Malicious code in vitest-agent (npm)

Analysis

vitest-agent@1.0.5 is a combosquat of the vitest test runner, shipping a trojanized copy of the nodemailer library. The postinstall hook (node lib/utils/index.js) spawns a detached child process running lib/utils/smtp-connection/index.js, which fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/UTUUE and executes it via new Function("require", ...). The payload URL is resolved at install time and the fetched code runs with full access to the installer's Node.js environment.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 03:29 PM
analyzed
Jul 1, 2026, 08:19 PM
weekly installs
170

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.