bubblestr@1.1.4
Malicious code in bubblestr (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1564.003 · Hidden Window
Analysis
bubblestr@1.1.4 runs a heavily obfuscated postinstall script (node index.js) that downloads a second-stage payload from a remote server, writes it to disk, and executes it via child_process with the window hidden. The script also suppresses all crash output by installing empty uncaughtException and unhandledRejection handlers, and uses javascript-obfuscator to conceal the C2 URL and payload logic from static inspection. The payload URL is constructed at runtime from an obfuscated string array and could not be extracted from static analysis alone.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 02:07 PM
- analyzed
- Jun 15, 2026, 02:08 PM
Related advisories
- texttweak-kit@1.0.0
- textify-kit@1.0.0
- strutil-kit@1.0.0
- str-master@1.0.11
- strmagic-kit@1.0.0
- string-utils-kit@1.0.0
- stringsculpt-kit@1.0.0
- stringfy-utils-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.