@rbxst/services@1.0.756
Malicious code in @rbxst/services (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting Interpreter
Analysis
The package's postinstall hook (scripts/postinstall.js) is a Windows-targeted multi-stage dropper. On Windows installs it downloads a ZIP archive from hxxps://files[.]catbox[.]moe/rp8idk[.]zip into the temp directory, extracts it with PowerShell Expand-Archive, then launches a detached, hidden pythonw.exe process that runs an exec_.py script from the extracted archive, and finally deletes the ZIP. This downloads and executes an unknown remote payload at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 10:04 AM
- analyzed
- Aug 7, 2026, 10:04 AM
Related advisories
- txrand@1.0.6
- streak-kit-map@1.0.0
- bnpl-blocks-atom-bnpl-faq-item@35.8.2
- dolyame-boxy-independent-bnpl-faq@35.8.7
- devplatform-react-mcp@35.5.6
- dolyame-boxy-independent-bnpl-main-title@35.5.6
- beaver-ui-popover-marker@35.5.8
- bigops-telephony-mock@35.7.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.