LWA-2026-12653 confirmed malware

cputil-node@0.6.6

Malicious code in cputil-node (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or InformationT1071.001 · Web Protocols

Analysis

cputil-node@0.6.6 ships the legitimate cputil wrapper with an injected obfuscated payload appended to its entry point. The published tarball's lib/index.js contains the genuine compiled wrapper (require("./cputil"); exports.default = cputil) followed on the same line by an added self-decoding loader: it sets global['_V']='8-npm3' and global['r']=require, defines a custom string-decoder function that permutes a character array using a constant-seeded index scheme, decodes a 30-character key, and then uses that key to decode two large encoded string blobs (roughly 1.2 KB and 2.4 KB) which are reassembled and executed through a dynamically constructed function. The decoded payload carries both HTTP-client and process-execution capability, so requiring the package can run commands and contact a remote endpoint. The loader is not produced by the package's own build (plain tsc + copyfiles) and is not javascript-obfuscator output — it is a bespoke permutation cipher, which is why generic obfuscation heuristics miss it. The rest of the tarball (the bundled .NET cputil runtime under lib/cputil/bin/linux and lib/cputil/bin/macos, including lib/cputil/bin/linux/cputil) is the legitimate Star cputil binary and is not the malicious component. No plaintext network indicator is recoverable from the injected block: the payload's C2 host, IP and URL path are encrypted inside the encoded blobs and are not present as readable strings in the package.

analyzed by
Leitwacht
first seen
Oct 6, 2026, 09:04 PM
analyzed
Oct 8, 2026, 11:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.