OpenSSF/OSV advisory MAL-2026-13990 confirms this npm version as malicious. On `npm install`, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in wct-st (npm)
Details
On `npm install`, the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated `web-component-tester`, consistent with a typosquat / dependency-confusion beacon shape.
Decision reason
OpenSSF Malicious Packages via OSV confirms wct-st@1.0.0 as malicious (MAL-2026-13990): Malicious code in wct-st (npm)