LWA-2026-11781 confirmed malware

opiumisbest@1.1.0

Malicious code in opiumisbest (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package ships an SVG (index.svg) that embeds an HTML page. When the SVG is opened in a browser, an inline script fetches a remote loader.js from a jsDelivr-hosted GitHub repository (TongSherbet/storage) and injects it as a script tag, executing attacker-controlled code in the page context. A bundled service worker (sw.js) performs the same remote-code load via importScripts from the same CDN. The remote payload is fetched fresh each hour (cache-busted with a timestamp query) from the following CDN mirrors: hxxps://cdn[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://quantil[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://fastly[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://testingcf[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://gcore[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://originfastly[.]jsdelivr[.]net/gh/TongSherbet/storage/, hxxps://jsdelivr[.]b-cdn[.]net/gh/TongSherbet/storage/. The package has no install-time lifecycle hooks; the malicious behaviour is the browser-side remote script injection.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 02:45 AM
analyzed
Aug 31, 2026, 02:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.