stringfy-utils-kit@1.0.0
Malicious code in stringfy-utils-kit (npm)
Analysis
Postinstall hook (bin/setup.js) launches a 9.8MB Windows PE binary (assets/setup-helper.exe) with hidden window, detached process, and stdio ignored — the binary runs silently in the background with no visible indication. The binary is a PyInstaller-packaged Python application containing network libraries (urllib3, requests, socket, ssl) and process-execution modules (subprocess, tempfile, shutil), enabling second-stage payload download, command execution, and data exfiltration. The package markets itself as a string manipulation utility but is installed via npm under a name (stringfy-utils-kit) that does not match its documented project name (string-master), and its only actual utility code is a benign facade.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 08:03 AM
- analyzed
- Jun 14, 2026, 08:04 AM
Related advisories
- sort-btree@2.1.4
- macos-ci-utils@1.0.1
- index-ulid@3.0.2
- obfus-jsxy@3.2.0
- ecto-rust-read-f3a9c1@1.0.2
- strapi-plugin-conresh-meeb@3.6.8
- tailwind-scrollbar-styles@4.0.3
- tailwind-container-queries@0.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.