testis-pack@1.0.0
Malicious code in testis-pack (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious FileT1055 · Process Injection
Analysis
The preinstall hook runs index.js, which decodes a hostname from charcode arrays and fetches a platform-specific binary from hxxps://sloth-antagonist[.]vercel[.]app/service/assets/fetchBinary (Windows) or /service/assets/fetchLinuxBinary (Linux). The binary is saved to ~/.local/share/WinMetrics/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows) and spawned as a detached background process with stdio ignored and the window hidden on Windows. The package also exports a thin XOR/CRC pack/unpack wrapper as a decoy module.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 08:09 AM
- analyzed
- Jul 8, 2026, 08:10 AM
Related advisories
- express-mongo-limit@2.0.1
- notifier-utils@1.3.7
- chai-as-staged@6.0.4
- chai-as-forgeted@9.24.6
- env-config-f281@1.0.0
- web-pool@2.3.5
- sort-btree@2.1.4
- poxios-chain@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.