LWA-2026-12385 confirmed malware

selfsigned-generator@1.0.0

Malicious code in selfsigned-generator (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting InterpreterT1071.001 · Web Protocols

Analysis

selfsigned-generator@1.0.0 is a trojanized certificate generator. Its bundled file sample/cert.pem is not a certificate but base64-encoded JavaScript that index.js decodes and executes via eval whenever the exported generateCertificates() function is called. The decoded payload fetches a remote script from hxxp://144[.]179[.]201[.]19/settings[.]php and pipes it into a detached python3/python process for execution, downloading and running arbitrary code on the installer's machine.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 03:18 PM
analyzed
Sep 24, 2026, 03:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.