LWA-2026-11314 confirmed malware
@finaxis/common-js@0.3.3
Malicious code in @finaxis/common-js (npm)
T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1082 · System Information DiscoveryT1071.004 · DNS
Analysis
@finaxis/common-js is a trojanized clone of the lodash library: it ships lodash's README verbatim but the actual dist/common-js.js is a 121KB javascript-obfuscator-obfuscated payload (encoded string-array with a custom decoder) rather than lodash source. When loaded, the obfuscated code performs host reconnaissance and issues a DNS TXT lookup to a hardcoded beacon domain as a command-and-control channel. The package impersonates lodash to trick installers into running the obfuscated recon/beacon payload.
- analyzed by
- Leitwacht
- first seen
- Aug 14, 2026, 09:25 PM
- analyzed
- Aug 14, 2026, 09:26 PM
Related advisories
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
- dolyame-ui-contenteditable@35.8.1
- dolyame-ui-mediainfohoc@35.8.1
- dolyame-ui-inputtime@35.8.1
- dolyame-ui-selectaccount@35.8.1
- dolyame-ui-stateutils@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.