LWA-2026-6479 MAL-2026-10436 ↗ confirmed malware

jest-formatter@1.0.0

Malicious code in jest-formatter (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1115 · Clipboard DataT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

jest-formatter@1.0.0 is a trojanized clone of a Jest formatter that exfiltrates the victim's credentials, crypto wallets, and sensitive files. On install, running `npm test` triggers a full data-theft pipeline: it scans the project directory and home drives for .env files, crypto wallet files (keystore, wallet.json, keypair.json, mnemonic.txt, seed.txt, credentials.json), SSH private keys (.pem/.p12/.pfx), shell history (bash/zsh/fish/PowerShell), clipboard contents, and development secrets (EVM private keys, Solana key arrays, mnemonics, AWS secrets, API tokens, npm tokens). All stolen data is uploaded via multipart HTTP POST to hxxps://trabalhos-flax[.]vercel[.]app/api/v1. The package also bundles a RAR archive (data-backup-single.rar) of unknown purpose.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 08:13 AM
analyzed
Jul 9, 2026, 08:14 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.