LWA-2026-10097 MAL-2026-12177 ↗ confirmed malware

devpack-conf@5.0.0

Malicious code in devpack-conf (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1082 · System Information Discovery

Analysis

devpack-conf@5.0.0 is a trojanized config-reading package whose index.js appends an eval(atob(...)) payload. On load it queries public Ethereum JSON-RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to locate a transaction from address 0x8a3322e5f3d311d30e6f0121063e9aDC24d90e5a, extracts the transaction's `to` field, and splits it into two IPv4 addresses. It then spawns a detached background node process that connects to those addresses on ports 80/443 and sends XOR-encoded requests to the paths /0x/cls and /0x/ls, retrieving and executing second-stage commands. The C2 infrastructure is rotated via the blockchain, so the beacon destinations change with each new transaction from the controlling address.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 08:36 AM
analyzed
Aug 5, 2026, 08:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.