LWA-2026-11907 MAL-2026-15970 ↗ confirmed malware

array-scala@1.2.5

Malicious code in array-scala (npm)

T1059.007 · JavaScriptT1059.003 · Windows Command ShellT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1195.002 · Compromise Software Supply Chain

Analysis

array-scala@1.2.5 is a trojanized clone of the legitimate array-scala utility. Its main module is obfuscated and, when required, acts as a multi-stage dropper: it creates a cache directory under the OS temp dir, writes an obfuscated payload into a node_modules subdirectory, and installs dependencies including axios, better-sqlite3, node-machine-id, socket[.]io-client, and (on Windows) koffi. It then spawns the Node.js runtime to execute the payload; on Windows it also writes a main.vbs file and runs it via wscript.exe with cmd /d /s /c. The bundled dependency set indicates hardware fingerprinting (node-machine-id), a socket[.]io command-and-control channel, HTTP exfiltration (axios), and local database access (better-sqlite3). The package also declares a dependency on itself (array-scala ^1.2.4).

analyzed by
Leitwacht
first seen
Sep 5, 2026, 07:40 PM
analyzed
Sep 5, 2026, 07:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.