VDB
KO

MAL-2026-13990

Malicious code in wct-st (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595) On `npm install`, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated `web-component-tester`, consistent with a typosquat / dependency-confusion beacon shape.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / wct-st

No fixed version published yet for wct-st (npm). Pin to a known-safe version or switch to an alternative.

References