LWA-2026-12248 MAL-2026-16328 ↗ confirmed malware

catwrestlinghuman@1.0.0

Malicious code in catwrestlinghuman (npm)

T1059.007 · JavaScriptT1027.010 · Command Obfuscation

Analysis

The package's postinstall hook runs `node index.js`, which is a 111KB script fully obfuscated with JSFuck (every string encoded as boolean/array token expressions). A second 126KB JSFuck-obfuscated file, extension.js, is bundled alongside. The package has no description, no repository, and no readable plaintext source anywhere, so the encoded payload's behaviour is not statically recoverable; the install-time execution of a fully-obfuscated script with no legitimate purpose is the malicious behaviour.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 07:00 PM
analyzed
Sep 18, 2026, 07:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.