hectorstatic@1.0.1
Malicious code in hectorstatic (npm)
Analysis
hectorstatic@1.0.1 is a trojanized copy of the FileSaver.js browser library with an injected remote-code-downloader appended to downloader.all.js and downloader.test.js. The injected code builds a URL to hxxps://s[.]jtm[.]pub/api/sp/lib?author=[.][.][.]&name=[.][.][.]&version=[.][.][.]&namespace=[.][.][.]&updateURL=[.][.][.]×tamp=[.][.]. and executes the response with eval(), fetching and running arbitrary remote code. The payload is gated to a daily limit of 15 requests and uses Greasemonkey/Tampermonkey APIs (GM_getValue, GM_setValue, GM_xmlhttpRequest, GM_info).
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 10:55 AM
- analyzed
- Aug 31, 2026, 10:55 AM
Related advisories
- telegramxjm@1.0.1
- classroomlearning@1.1.0
- opiumisbest@1.1.0
- eslint-prettier-js@0.0.1
- originaldevelopmentstelemetry@1.2.2
- developmentstelemetry@1.0.1
- node-request-utils@1.0.0
- mfaatest@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.