LWA-2026-6448 MAL-2026-10074 ↗ confirmed malware

testis-pack@1.0.0

Malicious code in testis-pack (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious FileT1055 · Process Injection

Analysis

The preinstall hook runs index.js, which decodes a hostname from charcode arrays and fetches a platform-specific binary from hxxps://sloth-antagonist[.]vercel[.]app/service/assets/fetchBinary (Windows) or /service/assets/fetchLinuxBinary (Linux). The binary is saved to ~/.local/share/WinMetrics/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows) and spawned as a detached background process with stdio ignored and the window hidden on Windows. The package also exports a thin XOR/CRC pack/unpack wrapper as a decoy module.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 08:09 AM
analyzed
Jul 8, 2026, 08:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.