LWA-2026-11654 confirmed malware
selfsigned-certificate@1.0.0
Malicious code in selfsigned-certificate (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.001 · Credentials In Files
Analysis
selfsigned-certificate@1.0.0 is a backdoored SSL-certificate generator. When generateCertificates(10) is called (a magic count value), the module POSTs to hxxps://jetpack[.]cv/wp-json/selfsigned-certs/v3/init with a hardcoded Basic-auth credential ([account]), base64-decodes the response, and executes it via eval() — arbitrary remote code execution from the attacker-controlled endpoint. The remote payload is served at runtime, not shipped in the tarball. C2 endpoint: hxxps://jetpack[.]cv/wp-json/selfsigned-certs/v3/init.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 09:37 AM
- analyzed
- Aug 27, 2026, 09:38 AM
Related advisories
- tailwindcss-form-styles@0.5.15
- tailwindcss-3d-animate@1.2.2
- dsh-tauri-panel-extension@0.4.0
- hydration-vli-ui@1.0.0
- tsrml612@1.14.0
- chai-as-otc@1.0.5
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.