LWA-2026-10712 confirmed malware

txrand@1.0.6

Malicious code in txrand (npm)

T1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

txrand@1.0.6 ships a base64-encoded payload in test_address_list.js that is decoded and eval'd when the library's transaction-generation function is used. The decoded payload downloads a remote script from hxxps://dorkobs[.]com/Wsw/inform[.]php via axios, writes it to the system temp directory as tmp_20260521, and executes it with python3 (or python on Windows) as a detached background process. This remote code download-and-execute behaviour is unrelated to the package's stated purpose of generating random ecommerce transaction data.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 08:40 AM
analyzed
Aug 7, 2026, 08:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.