LWA-2026-10712 confirmed malware
txrand@1.0.6
Malicious code in txrand (npm)
T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information
Analysis
txrand@1.0.6 ships a base64-encoded payload in test_address_list.js that is decoded and eval'd when the library's transaction-generation function is used. The decoded payload downloads a remote script from hxxps://dorkobs[.]com/Wsw/inform[.]php via axios, writes it to the system temp directory as tmp_20260521, and executes it with python3 (or python on Windows) as a detached background process. This remote code download-and-execute behaviour is unrelated to the package's stated purpose of generating random ecommerce transaction data.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 08:40 AM
- analyzed
- Aug 7, 2026, 08:40 AM
Related advisories
- khanbmnxls@1.0.0
- streak-cache-map@1.0.0
- ezdiscordbots@1.0.2
- hardhat-set@2.21.0
- npm-dc-dev@1.1.1
- dolyame-boxy-mobile-bnpl-card-gallery@35.9.5
- devplatform-spa-tokens@35.3.1
- dolyame-boxy-independent-bnpl-tiles@35.7.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.