LWA-2026-11509 MAL-2026-14305 ↗ confirmed malware

mc-provider@1.0.10

Malicious code in mc-provider (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

mc-provider depends on the malicious package supersig. When supersig is loaded it reads a DES-encrypted token (from node_modules/tchain-api/apps/docs/app/rsa.db, or a key supplied by the mkb-manager dependency), decrypts it with the hardcoded password "password", then spawns a detached node process and pipes the decrypted payload into its stdin for execution. This is a multi-stage dropper that runs an encrypted second-stage payload in a background process on install/require.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 06:30 PM
analyzed
Aug 19, 2026, 06:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.