MAL-2026-13990
Malicious code in wct-st (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595) On `npm install`, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated `web-component-tester`, consistent with a typosquat / dependency-confusion beacon shape.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for wct-st (npm). Pin to a known-safe version or switch to an alternative.