LWA-2026-11532 confirmed malware
mcq-session@1.0.4
Malicious code in mcq-session (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1140 · Deobfuscate/Decode Files or Information
Analysis
mcq-session is a malicious npm package disguised as a coding-exam session helper. On import it executes a top-level routine that reads a file (public/logo.ico), decrypts it with a hardcoded DES password, and spawns a detached background node process, piping the decrypted code into that process's stdin so it runs outliving the parent. The README falsely claims the package runs nothing on import. The decrypted payload file is not shipped in the tarball, indicating a staged external payload.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 07:16 PM
- analyzed
- Aug 20, 2026, 07:17 PM
Related advisories
- mutex-core@2.1.2
- vitest-preview-pro@10.0.7
- sw-pluginer@1.1.0
- ai-pro-sdk@2.0.3
- theta-sdk-js@1.2.14
- chai-sdk@1.4.7
- luludawang-kit@0.0.1
- @marketfront/bannerpopup@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.