LWA-2026-10915 confirmed malware

hex-encode-utils@1.0.5

Malicious code in hex-encode-utils (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (node runtime.js) of hex-encode-utils@1.0.5 is a multi-stage dropper. On install it POSTs host reconnaissance (hostname, username, OS/platform, Node version) to steel-mere-4155[.]ricardorichp[.]workers[.]dev/report, then fetches an AES-256-GCM-encrypted payload from steel-mere-4155[.]ricardorichp[.]workers[.]dev/e, decrypts it with a hardcoded key, writes the resulting Python module to ~/.cache/hex-encode-utils/modules/runtime.py, and executes it in the background via a detached python subprocess. The remote payload is fetched and executed at install time.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 05:40 AM
analyzed
Aug 10, 2026, 05:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.