mc-provider@1.0.10
Malicious code in mc-provider (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information
Analysis
mc-provider depends on the malicious package supersig. When supersig is loaded it reads a DES-encrypted token (from node_modules/tchain-api/apps/docs/app/rsa.db, or a key supplied by the mkb-manager dependency), decrypts it with the hardcoded password "password", then spawns a detached node process and pipes the decrypted payload into its stdin for execution. This is a multi-stage dropper that runs an encrypted second-stage payload in a background process on install/require.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 06:30 PM
- analyzed
- Aug 19, 2026, 06:33 PM
Related advisories
- @wizloft/harness-plugin-repository-files@0.1.1-alpha.3
- typecript-cli@1.0.0
- ranux-cloud@1.0.0
- @finaxis/common-js@0.3.3
- twcvhjlksdmx@1.0.0
- @coralxyz/anchor@0.30.2
- hardhat-cap@2.21.1
- dolyame-ui-draghoc@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.