LWA-2026-12034 MAL-2026-16138 ↗ confirmed malware

greensaver@1.2.2

Malicious code in greensaver (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1071.001 · Web Protocols

Analysis

greensaver is a trojanized clone of the micromatch glob library. Its preinstall and postinstall hooks run lib/greensaver.js, which decodes two base64-encoded payloads (lib/parse.ts.map and lib/init.ts.map) into temporary JS files, executes them, then deletes the artifacts. The decoded payload fetches an AES-256-CBC-encrypted session from an anonymous[.]com endpoint (authenticating with an x-service-token header), decrypts it using a key derived from the hardcoded passphrase 'myPassword123' with salt 'salt', and executes the decrypted content via eval — a remote code execution / C2 channel that runs at install time.

analyzed by
Leitwacht
first seen
Sep 11, 2026, 03:55 PM
analyzed
Sep 11, 2026, 03:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.