LWA-2026-5167 MAL-2026-6877 ↗ confirmed malware

sjs-builders@1.0.4

Malicious code in sjs-builders (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

On installation, the postinstall hook runs test.js which loads a heavily-obfuscated 52KB payload (index.js). The payload walks the filesystem from the current working directory, recursively searching for files matching specific extensions (likely credential and config files such as .env, SSH keys, and token files). For each matching file, it reads the contents and composes a multipart/form-data POST request combining the file data with the installer's process environment variables, then exfiltrates the payload to a remote server via axios over HTTPS. The C2 URL and targeted file extensions are runtime-decoded from obfuscated string tables to evade static analysis.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 12:48 AM
analyzed
Jun 14, 2026, 12:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.