LWA-2026-5192 confirmed malware

st-pathhelper@1.0.0

Malicious code in st-pathhelper (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1573.001 · Symmetric CryptographyT1059.007 · JavaScriptT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool Transfer

Analysis

A malicious npm package posing as a path-join helper (st-pathhelper@1.0.0). When imported and initialized, it POSTs the victim's operating system platform to a remote server at hxxps://gifpngstore[.]com/test/data[.]php via HTTPS, receives an RC4-encrypted payload (key: "steveJoe"), decrypts it, and executes the decrypted arbitrary JavaScript code via eval(). The C2 server at gifpngstore[.]com serves the encrypted second-stage payload. The package also ships unrelated wallet-address generator stubs (BTC/ERC/TRC) and a Budibase API client as camouflage for its malicious purpose.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 07:18 AM
analyzed
Jun 14, 2026, 07:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.