LWA-2026-11940 confirmed malware
shaon-video-downloader@1.0.2
Malicious code in shaon-video-downloader (npm)
T1027 · Obfuscated Files or InformationT1059.007 · JavaScript
Analysis
The package's entire main module (src/index.js) is a single obfuscated blob: a custom XOR decoder that decodes and eval()s a payload whenever the module is required. No readable implementation is shipped. The bundled README documents usage of a differently-named package (shaon-videos-downloader), indicating the code is a repackaged/impersonating build. The decoded payload's behaviour is not visible in the shipped source; the package should not be installed.
- analyzed by
- Leitwacht
- first seen
- Sep 7, 2026, 05:46 PM
- analyzed
- Sep 7, 2026, 05:47 PM
Related advisories
- node-helper@1.5.4
- date-fns-formatter@1.3.8
- tailwind-scrollbar-styles@4.0.3
- tailwind-container-queries@0.1.1
- caphsmgiwy@1.0.0
- xsjukcnv8low26@1.0.0
- node-net-pool@1.0.0
- exprss-helmet@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.