LWA-2026-10101 MAL-2026-12318 ↗ confirmed malware

@hoteldev/common@1.0.9

Malicious code in @hoteldev/common (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1573 · Encrypted ChannelT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

@hoteldev/common@1.0.9 ships an obfuscated payload in build/index.js (eval(atob(...))) that installs a command-and-control implant. On load it queries public Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) and the eth[.]blockscout[.]com API to locate transactions from a hardcoded address (0xa3322e5f3d331d330e6f0121063e9adc2490e5f1a), extracting IP addresses from transaction fields to derive C2 hosts. It then spawns a detached node process that connects to hxxp://{ip}:443/0x/cls and hxxp://{ip}:443/0x/ls, XOR-decoding command responses carried in the x-payload-b64 HTTP header. The implant uses the Ethereum blockchain as a covert channel to distribute its C2 infrastructure.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 10:06 AM
analyzed
Aug 5, 2026, 10:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.