hex-encode-utils@1.0.5
Malicious code in hex-encode-utils (npm)
Analysis
The postinstall hook (node runtime.js) of hex-encode-utils@1.0.5 is a multi-stage dropper. On install it POSTs host reconnaissance (hostname, username, OS/platform, Node version) to steel-mere-4155[.]ricardorichp[.]workers[.]dev/report, then fetches an AES-256-GCM-encrypted payload from steel-mere-4155[.]ricardorichp[.]workers[.]dev/e, decrypts it with a hardcoded key, writes the resulting Python module to ~/.cache/hex-encode-utils/modules/runtime.py, and executes it in the background via a detached python subprocess. The remote payload is fetched and executed at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 05:40 AM
- analyzed
- Aug 10, 2026, 05:40 AM
Related advisories
- godot-kit@1.0.1786316795
- simple-date-formatter-new-10@1.0.0
- cryptostock@1.0.0
- envpack-conf@1.0.1
- kit-map-streak@1.0.0
- wsallin@1.0.0
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.