MAL-2026-13990
Dashboard / Malicious Package / MAL-2026-13990
MAL-2026-13990
Summary: Malicious code in wct-st (npm)
Details: Source: amazon-inspector (3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595) On `npm install`, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated `web-component-tester`, consistent with a typosquat / dependency-confusion beacon shape.
References: https://www.npmjs.com/package/wct-st/v/1.0.0
Affected packages
Package
Name: wct-st
Purl: pkg:npm/wct-st
Affected ranges
Type: N/A
Events:
