LWA-2026-5961 MAL-2026-6491 ↗ confirmed malware

hexo-deployer-wrangler@1.0.4

Malicious code in hexo-deployer-wrangler (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

Trojanized update of hexo-deployer-wrangler. Version 1.0.3 was a legitimate Hexo deployer plugin (~4KB) wrapping the Cloudflare Wrangler CLI. Version 1.0.4 replaces index.js entirely with 5.2MB of heavily obfuscated JavaScript code using a ROT-character decoder and eval(), executing a hidden payload on require(). The benign first version established trust, then the malicious payload was pushed in a later update. The obfuscated payload's full behaviour cannot be determined from static analysis alone, but the size, structure, and delivery mechanism are consistent with credential harvesting or remote access payloads.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 09:19 AM
analyzed
Jun 25, 2026, 09:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.