LWA-2026-11584 confirmed malware
evm-validation@1.0.4
Malicious code in evm-validation (npm)
T1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
The package exports a `validated` function that, when called, sends its string argument to a remote endpoint at hxxps://e-api[.]netlify[.]app/ via an HTTP GET. The endpoint URL is obfuscated in the source (ROT13 cipher plus string reversal) to hide it. The package is presented as an EVM validation utility, but its only real behaviour is forwarding caller-supplied data to this remote host — a data-exfiltration beacon.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 04:58 AM
- analyzed
- Aug 24, 2026, 04:58 AM
Related advisories
- hydration-dim-ui@1.0.0
- mutex-thread@1.3.0
- shared-slot-gate@1.1.2
- async-critical-section@1.0.0
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- base65-33x@5.0.2
- developer-dashboard@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.