npm

wct-st @1.0.0

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC

Malicious

OSV ID

MAL-2026-13990

Ecosystem

npm

Summary

On npm install , the package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node.js version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded remote endpoint https://bhvte4h4.instances.poc.jchunt.top/wct-st. The beacon fires automatically with no consent, configuration, or opt-out. The package name resembles the deprecated web-component-tester , consistent with a typosquat / dependency-confusion beacon shape.

Source: amazon-inspector (3065a54d66ae4872334224443453c85f98c9ab8ae9d87df215bb51a5ba5e7595)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.