stringfy-utils-kit@1.0.0
Malicious code in stringfy-utils-kit (npm)
Analysis
Postinstall hook (bin/setup.js) launches a 9.8MB Windows PE binary (assets/setup-helper.exe) with hidden window, detached process, and stdio ignored — the binary runs silently in the background with no visible indication. The binary is a PyInstaller-packaged Python application containing network libraries (urllib3, requests, socket, ssl) and process-execution modules (subprocess, tempfile, shutil), enabling second-stage payload download, command execution, and data exfiltration. The package markets itself as a string manipulation utility but is installed via npm under a name (stringfy-utils-kit) that does not match its documented project name (string-master), and its only actual utility code is a benign facade.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 08:03 AM
- analyzed
- Jun 14, 2026, 08:04 AM
Related advisories
- sort-btree@2.1.4
- macos-ci-utils@1.0.1
- index-ulid@3.0.2
- obfus-jsxy@3.2.0
- ecto-rust-read-f3a9c1@1.0.2
- devplatform-spa-plugin-module-loader@35.8.5
- entropyeasybots@2.0.2
- @marketfront/bannerpopup@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.