LWA-2026-11957 confirmed malware

@davidov0516/string-utils@1.1.3

Malicious code in @davidov0516/string-utils (npm)

T1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1552.001 · Credentials In Files

Analysis

The package ships a live npm publish token in package/.env (NODE_AUTH_TOKEN). Its dist/index.js exports stringify() and randomBytes() functions that POST base64-encoded data to the remote endpoint hxxps://auth[.]publicnode1[.]online/v2, exfiltrating content to an external server under the guise of a string-utility library.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 10:48 AM
analyzed
Sep 9, 2026, 10:50 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.