LWA-2026-11669 confirmed malware

manager-thedate@1.0.16

Malicious code in manager-thedate (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

The package's main entry (index.js) exports a value read from an OpenSSL AES-encrypted blob (apps/docs/app/des.db, "Salted__" header) via apps/docs/app/theta.js, exposing it as desKey. The package is otherwise a Next.js/turbo monorepo template with no install hooks, no network calls, and no other executable payload. The encrypted blob is shipped as a key inside a package described as a "Theta Data API" developer platform; no code in the package decrypts or uses it. No network IOC was observed.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 07:36 PM
analyzed
Aug 27, 2026, 07:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.