LWA-2026-11532 confirmed malware

mcq-session@1.0.4

Malicious code in mcq-session (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1140 · Deobfuscate/Decode Files or Information

Analysis

mcq-session is a malicious npm package disguised as a coding-exam session helper. On import it executes a top-level routine that reads a file (public/logo.ico), decrypts it with a hardcoded DES password, and spawns a detached background node process, piping the decrypted code into that process's stdin so it runs outliving the parent. The README falsely claims the package runs nothing on import. The decrypted payload file is not shipped in the tarball, indicating a staged external payload.

analyzed by
Leitwacht
first seen
Aug 20, 2026, 07:16 PM
analyzed
Aug 20, 2026, 07:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.