LWA-2026-11800 confirmed malware

hectorstatic@1.0.1

Malicious code in hectorstatic (npm)

T1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

hectorstatic@1.0.1 is a trojanized copy of the FileSaver.js browser library with an injected remote-code-downloader appended to downloader.all.js and downloader.test.js. The injected code builds a URL to hxxps://s[.]jtm[.]pub/api/sp/lib?author=[.][.][.]&name=[.][.][.]&version=[.][.][.]&namespace=[.][.][.]&updateURL=[.][.][.]&timestamp=[.][.]. and executes the response with eval(), fetching and running arbitrary remote code. The payload is gated to a daily limit of 15 requests and uses Greasemonkey/Tampermonkey APIs (GM_getValue, GM_setValue, GM_xmlhttpRequest, GM_info).

analyzed by
Leitwacht
first seen
Aug 31, 2026, 10:55 AM
analyzed
Aug 31, 2026, 10:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.