st-pathhelper@1.0.0
Malicious code in st-pathhelper (npm)
Analysis
A malicious npm package posing as a path-join helper (st-pathhelper@1.0.0). When imported and initialized, it POSTs the victim's operating system platform to a remote server at hxxps://gifpngstore[.]com/test/data[.]php via HTTPS, receives an RC4-encrypted payload (key: "steveJoe"), decrypts it, and executes the decrypted arbitrary JavaScript code via eval(). The C2 server at gifpngstore[.]com serves the encrypted second-stage payload. The package also ships unrelated wallet-address generator stubs (BTC/ERC/TRC) and a Budibase API client as camouflage for its malicious purpose.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 07:18 AM
- analyzed
- Jun 14, 2026, 07:18 AM
Related advisories
- protectstraizolib@1.0.8
- period-newline@0.1.0
- chalk-plus-js@7.0.4
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- statist-browser-typed-client-mb.reliability.android.metrics@20.9.3
- sme-crm-services-sme-crm-services-core@20.1.4
- beaver-ui-icon-lock@12.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.