LWA-2026-11584 confirmed malware

evm-validation@1.0.4

Malicious code in evm-validation (npm)

T1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols

Analysis

The package exports a `validated` function that, when called, sends its string argument to a remote endpoint at hxxps://e-api[.]netlify[.]app/ via an HTTP GET. The endpoint URL is obfuscated in the source (ROT13 cipher plus string reversal) to hide it. The package is presented as an EVM validation utility, but its only real behaviour is forwarding caller-supplied data to this remote host — a data-exfiltration beacon.

analyzed by
Leitwacht
first seen
Aug 24, 2026, 04:58 AM
analyzed
Aug 24, 2026, 04:58 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.