LWA-2026-12642 confirmed malware

random-certs@0.0.1

Malicious code in random-certs (npm)

T1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or InformationT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1059.006 · PythonT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web Service

Analysis

random-certs@0.0.1 presents itself as a random self-signed certificate generator, but index.js hides a remote-code dropper. Its loadSampleCertificate() function reads the bundled file sample/cert.pem, strips the PEM header/footer, base64-decodes the body and passes the result to eval(); generateCertificates() calls this on every invocation, so the hidden code runs as soon as the advertised API is used. The file named sample/cert.pem is not a certificate — it decodes to JavaScript that base64-decodes an embedded URL, fetches it, and pipes the response body into a detached interpreter process: spawn('python3' on POSIX, 'python' on win32, ['-'], {stdio:['pipe','ignore','ignore'], detached:true, windowsHide:true}) followed by stdin.write(body), stdin.end() and unref(), with all errors silently swallowed. The fetched content is only executed if its content-type is not text/html, a guard against Google Drive's HTML interstitial. The staging URL is a Google Drive download link (drive[.]usercontent[.]google[.]com/download?id=1y4LSiUb4PZSgJKBtEVJMDNnl3Sr7kbSy), so the second stage is fetched from a legitimate web service rather than a fixed attacker domain. The encoded_cert and encoded_key constants inside the payload are unused decoys. The package declares no lifecycle scripts, so the payload is triggered by calling generateCertificates() rather than at install time.

analyzed by
Leitwacht
first seen
Oct 7, 2026, 06:46 AM
analyzed
Oct 7, 2026, 06:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.