LWA-2026-0065 MAL-2026-4823 ↗ confirmed malware

msc-terminal@3.2.0

Malicious code in msc-terminal (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The package's install hook executes a bundled script that re-spawns itself as a detached, output-suppressed process for persistence and evasion. It ships an 836KB heavily obfuscated payload (dictionary-array obfuscation, base64 decoding via atob) that uses child_process and fetch for command execution and network exfiltration.

analyzed by
Leitwacht
first seen
May 26, 2026, 05:22 PM
analyzed
May 26, 2026, 07:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.