LWA-2026-5330 MAL-2026-6900 ↗ confirmed malware

txs-data@1.0.1

Malicious code in txs-data (npm)

T1059.007 · JavaScriptT1059.006 · PythonT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1195.002 · Compromise Software Supply Chain

Analysis

Package txs-data@1.0.1 masquerades as an e-commerce transaction-data generator but contains a hidden second-stage dropper. The index.js exports a function that reads a companion file (test_address_list.js), removes a 0x prefix from each line, base64-decodes the result, and evals the decoded JavaScript. The decoded payload decodes a base64-embedded C2 URL pointing to dct0per[.]com/app/aws=, appends /bag.php, downloads the remote script via axios into the system temp directory (tmp_20260202), and executes it as a detached Python process using python3/python. The payload runs automatically whenever the exported getTransactions() function is called.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 07:35 AM
analyzed
Jun 15, 2026, 07:36 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.