LWA-2026-12267 MAL-2026-16317 ↗ confirmed malware

testmgkregme@1.0.1

Malicious code in testmgkregme (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or Information

Analysis

The package executes a multi-stage obfuscated payload at install time. Its binding.gyp runs `node index.js` during the node-gyp configure step. index.js is a single 2.9MB obfuscated line that Caesar-decodes a character-code array to reconstruct source, imports node:crypto, and uses AES-128-GCM (createDecipher with a hex key, hex IV, and 16-byte auth tag) to decrypt several embedded base64 blobs, then evals the decrypted result. The decrypted second-stage content is not statically readable; the package's real behaviour is delivered only after this decrypt-and-eval chain runs.

analyzed by
Leitwacht
first seen
Sep 19, 2026, 05:42 AM
analyzed
Sep 19, 2026, 05:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.