LWA-2026-5199 confirmed malware

stringsculpt-kit@1.0.0

Malicious code in stringsculpt-kit (npm)

T1059.007 · JavaScriptT1059.003 · Windows Command ShellT1564.003 · Hidden WindowT1027 · Obfuscated Files or InformationT1204.002 · Malicious File

Analysis

The package stringsculpt-kit@1.0.0 is a string-manipulation utility facade that acts as a dropper for a Windows PE executable. On installation, the postinstall script (bin/setup.js) spawns assets/setup-helper.exe (~9.8MB) with detached:true, windowsHide:true, and stdio:'ignore' — running the binary silently in the background out of sight. The bundled native executable accounts for 99.5% of the package's size, while the published library code (dist/index.js) is a trivial string-utility shim included as cover.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 08:18 AM
analyzed
Jun 14, 2026, 08:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.