texttweak-kit@1.0.0
Malicious code in texttweak-kit (npm)
Analysis
On npm install, the postinstall hook in bin/setup.js spawns assets/setup-helper.exe as a detached hidden background Windows process with no console output. The executable (9.8MB) is a PyInstaller-packed Python binary that bundles requests, urllib3, http.client, socket, ssl, subprocess, multiprocessing, base64, hashlib, hmac, and netrc — a complete C2 implant framework with capabilities for network communication, command execution, and credential access from the victim's machine. The package's JavaScript library at dist/index.js is a decoy string-manipulation library unrelated to the malicious payload. The package does not ship the installer's tokens — the payload is the implanted PE binary itself.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 10:48 PM
- analyzed
- Jun 14, 2026, 10:49 PM
Related advisories
- npm-scanner@1.0.0
- nodecheck-health@1.0.0
- gpt-terminal-cli@1.0.0
- ezdiscordbots@1.0.2
- zredis-typed@1.0.127
- yian666aikf@1.0.3
- textify-kit@1.0.0
- strutil-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.