-= Per source details. Do not edit below this line.=-
On npm install, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated web-component-tester, consistent with a typosquat / dependency-confusion beacon shape.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017710",
"import_time": "2026-08-13T21:50:20.233851636Z",
"sha256": "3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595",
"versions": [
"1.0.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-13T21:39:27Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"tlsh": "ed0123c1d2b55a7127b852c068f1af0793bbf223370220b579c404e92f8d0f5003119d",
"sha256": "a8ec809c549c9e9e35dc4a681f4171a28477344863a71f5f7ae1caa0579c0aef"
}
],
"package_integrity": [
{
"filename": "wct-st-1.0.0.tgz",
"hashes": {
"sha512_sri": "sha512-/yu/DV8r41Wl/7vOQe4K4IBiOg8pbAHkj3UrZRt0GdZZ+5keMKFuFNmGpOIn9kRGk4BbLU+PeHs1ePpr/Fc22g==",
"sha1": "e1b5e2517bc914ea5b55e4a8294ce2a8f75064bc"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wct-st/MAL-2026-13990.json"