LWA-2026-11544 confirmed malware

rust-testing-utils@2.3.0

Malicious code in rust-testing-utils (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

rust-testing-utils@2.3.0 is a trojanized logger-style package whose main module spawns a detached background node subprocess (lib/caller.js) on require. That subprocess base64-decodes a hardcoded URL (hxxps://api[.]jsonstorage[.]io/v1/json/2ef8c758-a96f-4592-b036-2b5b5f9c9c5f/f89e8264-86c2-4680-94d9-c3f5c59370f), fetches it with header x-secret-key: X, reads the response's "cookie" field, and executes it as JavaScript via the Function constructor with full require access, retrying up to 5 times. This is a remote-code-execution loader: the package downloads and runs arbitrary code from a remote JSON-storage endpoint at runtime.

analyzed by
Leitwacht
first seen
Aug 21, 2026, 11:31 PM
analyzed
Aug 21, 2026, 11:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.