strmagic-kit@1.0.0
Malicious code in strmagic-kit (npm)
Analysis
The npm package strmagic-kit@1.0.0 is a supply-chain malware package. Its postinstall hook (bin/setup.js) silently spawns a 9.8MB Windows PE executable (assets/setup-helper.exe) as a background process with hidden window and detached lifecycle, so it continues running after the installation completes. The executable is a PyInstaller bundle containing Python libraries for network communication, file extraction, and subprocess management — a fully self-contained payload. The dist/index.js entry point is a trivial decoy string-manipulation library that bears no relation to the bundled executable. Only affects Windows systems; the executable runs invisibly on npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 08:33 AM
- analyzed
- Jun 14, 2026, 08:34 AM
Related advisories
- string-utils-kit@1.0.0
- stringsculpt-kit@1.0.0
- stringfy-utils-kit@1.0.0
- rollup-packages-polyfill-core@0.5.0
- prettier-lint-lenz@2.6.4
- vite-react-toolkit@1.0.1
- obfus-jsxy@3.2.0
- vite-tsconfig@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.