LWA-2026-12602 confirmed malware

solidity-map@2.21.0

Malicious code in solidity-map (npm)

T1195.002 · Compromise Software Supply ChainT1036.005 · Match Legitimate Resource Name or LocationT1027 · Obfuscated Files or InformationT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

solidity-map@2.21.0 is a trojanized clone of the pino logging library. Its README, type definitions and docs are copied verbatim from pino, but the package name, description and author metadata are unrelated to that project, and index.js exports a stub Express middleware rather than pino's API. The real payload is lib/config.js (4.37 MB), a heavily obfuscated javascript-obfuscator bundle using a string-array decoder and \x-escaped constants; it is loaded via require('./lib/config') from index.js, so it executes as soon as the package is imported. On execution it fingerprints the host (hostname, OS, username, platform, timestamp) and beacons it as JSON to hxxp://167[.]88[.]172[.]33:8087/api/log and hxxp://167[.]88[.]172[.]33:8087/api/notify, then uploads a generated sysinfo.txt file via multipart/form-data POST to hxxp://167[.]88[.]172[.]33:8085/upload. Requests carry axios/1.20.0 user agents and custom Userkey/Validation headers. IOCs: C2 167[.]88[.]172[.]33 ports 8085 (/upload) and 8087 (/api/log, /api/notify).

analyzed by
Leitwacht
first seen
Oct 5, 2026, 07:01 PM
analyzed
Oct 5, 2026, 07:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.