LWA-2026-11386 confirmed malware

rand-tx-sdk@1.0.6

Malicious code in rand-tx-sdk (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

rand-tx-sdk@1.0.6 is a disguised remote-code downloader. Its exported getTransactions() function triggers an eval of a base64-encoded blob that downloads a Python script from hxxps://dorians[.]com/assets/exlorians/inform[.]php, writes it to the system temp directory as tmp_20260521, and executes it with python3 (or python on Windows) as a detached background process. The package presents itself as a random ecommerce-transaction data generator, but the download-and-execute of a remote script is its actual behavior.

analyzed by
Leitwacht
first seen
Aug 17, 2026, 02:28 AM
analyzed
Aug 17, 2026, 02:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.