txs-data@1.0.1
Malicious code in txs-data (npm)
Analysis
Package txs-data@1.0.1 masquerades as an e-commerce transaction-data generator but contains a hidden second-stage dropper. The index.js exports a function that reads a companion file (test_address_list.js), removes a 0x prefix from each line, base64-decodes the result, and evals the decoded JavaScript. The decoded payload decodes a base64-embedded C2 URL pointing to dct0per[.]com/app/aws=, appends /bag.php, downloads the remote script via axios into the system temp directory (tmp_20260202), and executes it as a detached Python process using python3/python. The payload runs automatically whenever the exported getTransactions() function is called.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 07:35 AM
- analyzed
- Jun 15, 2026, 07:36 AM
Related advisories
- solana-token-api@1.0.0
- pocbitbarrontest@1.0.0
- self-certificate@1.0.0
- meowmeow111@1.0.0
- meowmeow11001@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.