LWA-2026-11807 confirmed malware

chromatitle-js@1.0.0

Malicious code in chromatitle-js (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1082 · System Information Discovery

Analysis

chromatitle-js is a terminal-color library that runs a hidden bootstrap on import. Its main entry point (src/index.js) calls _bootstrap() from src/utils/bootstrap.js, a 58KB obfuscated script that imports child_process, https/http, fs, os, path and stream. On import it downloads a remote payload to the OS temporary directory, chmods it executable, and spawns it via child_process. The download URL is concealed inside an obfuscated string array. A color-formatting library has no legitimate reason to download and execute remote binaries.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 08:59 PM
analyzed
Aug 31, 2026, 09:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.