LWA-2026-5382 MAL-2026-5930 ↗ confirmed malware

bubblestr@1.1.4

Malicious code in bubblestr (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1564.003 · Hidden Window

Analysis

bubblestr@1.1.4 runs a heavily obfuscated postinstall script (node index.js) that downloads a second-stage payload from a remote server, writes it to disk, and executes it via child_process with the window hidden. The script also suppresses all crash output by installing empty uncaughtException and unhandledRejection handlers, and uses javascript-obfuscator to conceal the C2 URL and payload logic from static inspection. The payload URL is constructed at runtime from an obfuscated string array and could not be extracted from static analysis alone.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 02:07 PM
analyzed
Jun 15, 2026, 02:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.