LWA-2026-12788 confirmed malware

truffle-kit@3.3.2

Malicious code in truffle-kit (npm)

Analysis

Disguised as a logging library, the package exports a middleware that launches a hidden, detached background Node process. That process decodes a base64-obfuscated URL and a custom authentication header, POSTs to a remote server, and executes whatever JavaScript is returned using the Function constructor, passing it the require function, so the remote operator gets arbitrary code execution on the host. Console output is suppressed during execution and the request is retried up to five times.

analyzed by
Leitwacht
first seen
Oct 9, 2026, 11:29 AM
analyzed
Oct 9, 2026, 12:00 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.