LWA-2026-11807 confirmed malware
chromatitle-js@1.0.0
Malicious code in chromatitle-js (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1082 · System Information Discovery
Analysis
chromatitle-js is a terminal-color library that runs a hidden bootstrap on import. Its main entry point (src/index.js) calls _bootstrap() from src/utils/bootstrap.js, a 58KB obfuscated script that imports child_process, https/http, fs, os, path and stream. On import it downloads a remote payload to the OS temporary directory, chmods it executable, and spawns it via child_process. The download URL is concealed inside an obfuscated string array. A color-formatting library has no legitimate reason to download and execute remote binaries.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 08:59 PM
- analyzed
- Aug 31, 2026, 09:00 PM
Related advisories
- tailwindcss-forms-style@0.1.2
- tailwindcss-3d-styles@1.2.2
- fuels-versions@1.0.0
- autobahn-electron-probe@99.99.1
- com.db.autobahn.notification-center-electron@88.88.1
- node-request-utils@1.0.0
- cbc97b7a@1.1787999998.0
- test__123q1@2.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.