LWA-2026-12370 MAL-2026-17302 ↗ confirmed malware

solidity-lock@2.21.0

Malicious code in solidity-lock (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

solidity-lock@2.21.0 is a trojanized clone of the pino logging library: it ships pino's source tree verbatim under an unrelated package name, with a 4MB obfuscated file lib/config.js injected as the payload. The package's main entry (index.js) requires lib/config, so loading the package executes the obfuscated code. lib/config.js is javascript-obfuscator output: a large hex-escaped string array with a custom decoder and thousands of _0x-style identifiers and escaped method references, making its runtime behaviour unreadable. The obfuscated payload's network destinations and actions could not be recovered from the encoded strings; the staging mechanism is a require-time executed obfuscated module bundled inside a cloned logging package.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 06:06 PM
analyzed
Sep 23, 2026, 06:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.