LWA-2026-11669 confirmed malware
manager-thedate@1.0.16
Malicious code in manager-thedate (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
The package's main entry (index.js) exports a value read from an OpenSSL AES-encrypted blob (apps/docs/app/des.db, "Salted__" header) via apps/docs/app/theta.js, exposing it as desKey. The package is otherwise a Next.js/turbo monorepo template with no install hooks, no network calls, and no other executable payload. The encrypted blob is shipped as a key inside a package described as a "Theta Data API" developer platform; no code in the package decrypts or uses it. No network IOC was observed.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 07:36 PM
- analyzed
- Aug 27, 2026, 07:37 PM
Related advisories
- vitest-chalk-pro@10.0.7
- shadowmd@8.6.87
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- tailwindcss-form-styles@0.5.15
- tailwindcss-3d-animate@1.2.2
- htps-provider@1.0.11
- @flagship-io/openfeature-provider-js@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.