array-scala@1.2.5
Malicious code in array-scala (npm)
Analysis
array-scala@1.2.5 is a trojanized clone of the legitimate array-scala utility. Its main module is obfuscated and, when required, acts as a multi-stage dropper: it creates a cache directory under the OS temp dir, writes an obfuscated payload into a node_modules subdirectory, and installs dependencies including axios, better-sqlite3, node-machine-id, socket[.]io-client, and (on Windows) koffi. It then spawns the Node.js runtime to execute the payload; on Windows it also writes a main.vbs file and runs it via wscript.exe with cmd /d /s /c. The bundled dependency set indicates hardware fingerprinting (node-machine-id), a socket[.]io command-and-control channel, HTTP exfiltration (axios), and local database access (better-sqlite3). The package also declares a dependency on itself (array-scala ^1.2.4).
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 07:40 PM
- analyzed
- Sep 5, 2026, 07:41 PM
Related advisories
- mfa-js@1.0.4
- moidevy@1.0.0
- @opezneppelin/contracts@5.0.2
- @ethers-js/contracts@6.9.0
- sme-rko-finance-front-operations-domain@35.8.1
- dolyame-boxy-independent-bnpl-product-grid@35.9.2
- dolyame-boxy-desktop-bnpl-text-block@35.9.7
- bnpl-blocks-atom-bnpl-integrations-breadcrumbs@35.2.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.