LWA-2026-11314 confirmed malware

@finaxis/common-js@0.3.3

Malicious code in @finaxis/common-js (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1082 · System Information DiscoveryT1071.004 · DNS

Analysis

@finaxis/common-js is a trojanized clone of the lodash library: it ships lodash's README verbatim but the actual dist/common-js.js is a 121KB javascript-obfuscator-obfuscated payload (encoded string-array with a custom decoder) rather than lodash source. When loaded, the obfuscated code performs host reconnaissance and issues a DNS TXT lookup to a hardcoded beacon domain as a command-and-control channel. The package impersonates lodash to trick installers into running the obfuscated recon/beacon payload.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 09:25 PM
analyzed
Aug 14, 2026, 09:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.