LWA-2026-11940 confirmed malware

shaon-video-downloader@1.0.2

Malicious code in shaon-video-downloader (npm)

T1027 · Obfuscated Files or InformationT1059.007 · JavaScript

Analysis

The package's entire main module (src/index.js) is a single obfuscated blob: a custom XOR decoder that decodes and eval()s a payload whenever the module is required. No readable implementation is shipped. The bundled README documents usage of a differently-named package (shaon-videos-downloader), indicating the code is a repackaged/impersonating build. The decoded payload's behaviour is not visible in the shipped source; the package should not be installed.

analyzed by
Leitwacht
first seen
Sep 7, 2026, 05:46 PM
analyzed
Sep 7, 2026, 05:47 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.