MAL-2026-13990

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wct-st/MAL-2026-13990.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13990
Published
2026-08-13T21:39:27Z
Modified
2026-08-13T22:00:14.118688303Z
Summary
Malicious code in wct-st (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595)

On npm install, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated web-component-tester, consistent with a typosquat / dependency-confusion beacon shape.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-017710",
            "import_time": "2026-08-13T21:50:20.233851636Z",
            "sha256": "3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595",
            "versions": [
                "1.0.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-13T21:39:27Z"
        }
    ]
}
References
Credits

Affected packages

npm / wct-st

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "postinstall.js",
            "tlsh": "ed0123c1d2b55a7127b852c068f1af0793bbf223370220b579c404e92f8d0f5003119d",
            "sha256": "a8ec809c549c9e9e35dc4a681f4171a28477344863a71f5f7ae1caa0579c0aef"
        }
    ],
    "package_integrity": [
        {
            "filename": "wct-st-1.0.0.tgz",
            "hashes": {
                "sha512_sri": "sha512-/yu/DV8r41Wl/7vOQe4K4IBiOg8pbAHkj3UrZRt0GdZZ+5keMKFuFNmGpOIn9kRGk4BbLU+PeHs1ePpr/Fc22g==",
                "sha1": "e1b5e2517bc914ea5b55e4a8294ce2a8f75064bc"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wct-st/MAL-2026-13990.json"