LWA-2026-5199 confirmed malware
stringsculpt-kit@1.0.0
Malicious code in stringsculpt-kit (npm)
T1059.007 · JavaScriptT1059.003 · Windows Command ShellT1564.003 · Hidden WindowT1027 · Obfuscated Files or InformationT1204.002 · Malicious File
Analysis
The package stringsculpt-kit@1.0.0 is a string-manipulation utility facade that acts as a dropper for a Windows PE executable. On installation, the postinstall script (bin/setup.js) spawns assets/setup-helper.exe (~9.8MB) with detached:true, windowsHide:true, and stdio:'ignore' — running the binary silently in the background out of sight. The bundled native executable accounts for 99.5% of the package's size, while the published library code (dist/index.js) is a trivial string-utility shim included as cover.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 08:18 AM
- analyzed
- Jun 14, 2026, 08:19 AM
Related advisories
- stringfy-utils-kit@1.0.0
- rollup-packages-polyfill-core@0.5.0
- prettier-lint-lenz@2.6.4
- vite-react-toolkit@1.0.1
- obfus-jsxy@3.2.0
- vite-tsconfig@1.1.2
- bubblestring@1.1.4
- node-env-resolve@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.