MAL-2026-13990

    Dashboard / Malicious Package / MAL-2026-13990

    MAL-2026-13990

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in wct-st (npm)

    Details: Source: amazon-inspector (3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595) On `npm install`, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated `web-component-tester`, consistent with a typosquat / dependency-confusion beacon shape.

    Affected packages

    Package

    Name: wct-st

    Purl: pkg:npm/wct-st

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-13990 | CVE-DB