LWA-2026-11322 confirmed malware

ranux-cloud@1.0.0

Malicious code in ranux-cloud (npm)

T1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

ranux-cloud@1.0.0 ships a single obfuscated entry file (index.js, ~3.1MB) that acts as a loader. On require, it imports node:crypto, constructs a decipher, decrypts a large embedded encrypted blob, and executes the decrypted payload, then wipes the key/IV/auth-tag buffers from memory. The code is obfuscated with a large encoded string array and custom decoder, so the payload's behaviour is not visible statically. No network endpoint was observed in the static analysis; the package's stated purpose (a network socket/protocol engine) is not substantiated by any readable implementation.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 10:45 AM
analyzed
Aug 15, 2026, 10:48 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.