LWA-2026-11957 confirmed malware
@davidov0516/string-utils@1.1.3
Malicious code in @davidov0516/string-utils (npm)
T1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1552.001 · Credentials In Files
Analysis
The package ships a live npm publish token in package/.env (NODE_AUTH_TOKEN). Its dist/index.js exports stringify() and randomBytes() functions that POST base64-encoded data to the remote endpoint hxxps://auth[.]publicnode1[.]online/v2, exfiltrating content to an external server under the guise of a string-utility library.
- analyzed by
- Leitwacht
- first seen
- Sep 9, 2026, 10:48 AM
- analyzed
- Sep 9, 2026, 10:50 AM
Related advisories
- polygon-toolkits-validator@1.1.4
- @lekzo_dev/amprem@1.0.4
- amprem@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- xsjukcnv8low26@1.0.0
- bamru@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.