LWA-2026-11386 confirmed malware
rand-tx-sdk@1.0.6
Malicious code in rand-tx-sdk (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
rand-tx-sdk@1.0.6 is a disguised remote-code downloader. Its exported getTransactions() function triggers an eval of a base64-encoded blob that downloads a Python script from hxxps://dorians[.]com/assets/exlorians/inform[.]php, writes it to the system temp directory as tmp_20260521, and executes it with python3 (or python on Windows) as a detached background process. The package presents itself as a random ecommerce-transaction data generator, but the download-and-execute of a remote script is its actual behavior.
- analyzed by
- Leitwacht
- first seen
- Aug 17, 2026, 02:28 AM
- analyzed
- Aug 17, 2026, 02:28 AM
Related advisories
- syjoy@1.0.0
- typescipt-core@1.0.0
- comander-lib@1.0.0
- axois-http@1.0.0
- typscript-core@1.0.0
- typscript-cli@1.0.0
- typescipt-cli@1.0.0
- loadashjs@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.