analysis-chart@2.0.8
Malicious code in analysis-chart (npm)
Analysis
analysis-chart@2.0.8 is a trojanized package masquerading as a chart-analysis library. On npm install, the postinstall script (install-hook.js) downloads an XOR-encrypted Windows binary from hxxps://github[.]com/Dimitrijenco/Sticky_note/releases/download/v6/payload[.]bin, decrypts it in memory, and uses the ffi-napi native binding to call Windows kernel32 functions (VirtualAlloc, RtlMoveMemory, VirtualProtect, CreateThread) to inject the decrypted PE payload directly into the node.exe process memory — a reflective shellcode loader that never touches disk. The script silently catches errors to avoid alerting the user.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 10:30 PM
- analyzed
- Jun 22, 2026, 10:30 PM
Related advisories
- web3-token-helper@1.1.3
- zod-pino@1.0.122
- node-core-libs@1.0.0
- tailwindcss-effector@1.7.0
- assertcore@3.1.7
- chalk-ultra@12.0.3
- test-package-sajsdkashdj@2.1.6
- node-fetch-utils@1.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.