LWA-2026-5197 confirmed malware

stringfy-utils-kit@1.0.0

Malicious code in stringfy-utils-kit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1204.002 · Malicious FileT1564.003 · Hidden WindowT1480 · Execution Guardrails

Analysis

Postinstall hook (bin/setup.js) launches a 9.8MB Windows PE binary (assets/setup-helper.exe) with hidden window, detached process, and stdio ignored — the binary runs silently in the background with no visible indication. The binary is a PyInstaller-packaged Python application containing network libraries (urllib3, requests, socket, ssl) and process-execution modules (subprocess, tempfile, shutil), enabling second-stage payload download, command execution, and data exfiltration. The package markets itself as a string manipulation utility but is installed via npm under a name (stringfy-utils-kit) that does not match its documented project name (string-master), and its only actual utility code is a benign facade.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 08:03 AM
analyzed
Jun 14, 2026, 08:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.