LWA-2026-12385 confirmed malware
selfsigned-generator@1.0.0
Malicious code in selfsigned-generator (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting InterpreterT1071.001 · Web Protocols
Analysis
selfsigned-generator@1.0.0 is a trojanized certificate generator. Its bundled file sample/cert.pem is not a certificate but base64-encoded JavaScript that index.js decodes and executes via eval whenever the exported generateCertificates() function is called. The decoded payload fetches a remote script from hxxp://144[.]179[.]201[.]19/settings[.]php and pipes it into a detached python3/python process for execution, downloading and running arbitrary code on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 03:18 PM
- analyzed
- Sep 24, 2026, 03:23 PM
Related advisories
- simple-date-formatter-new-15@1.0.0
- n8n-nodes-flowstats@1.0.0
- n8n-nodes-moonlet-utils@1.0.0
- n8n-nodes-moonlet-helpers@1.0.0
- tldriver@0.0.1
- testmgkregme@1.0.1
- catwrestlingbird@1.0.0
- chai-testing@1.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.