testmgkregme@1.0.1
Malicious code in testmgkregme (npm)
Analysis
The package executes a multi-stage obfuscated payload at install time. Its binding.gyp runs `node index.js` during the node-gyp configure step. index.js is a single 2.9MB obfuscated line that Caesar-decodes a character-code array to reconstruct source, imports node:crypto, and uses AES-128-GCM (createDecipher with a hex key, hex IV, and 16-byte auth tag) to decrypt several embedded base64 blobs, then evals the decrypted result. The decrypted second-stage content is not statically readable; the package's real behaviour is delivered only after this decrypt-and-eval chain runs.
- analyzed by
- Leitwacht
- first seen
- Sep 19, 2026, 05:42 AM
- analyzed
- Sep 19, 2026, 05:46 AM
Related advisories
- punypump@1.2.4
- discord-mfa@3.0.0
- js-soul@1.0.4
- mcq-session@1.0.4
- sw-pluginer@1.1.0
- tailwind-custom-forms@0.5.2
- theta-sdk-js@1.2.14
- luludawang-kit@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.