hexo-deployer-wrangler@1.0.4
Malicious code in hexo-deployer-wrangler (npm)
Analysis
Trojanized update of hexo-deployer-wrangler. Version 1.0.3 was a legitimate Hexo deployer plugin (~4KB) wrapping the Cloudflare Wrangler CLI. Version 1.0.4 replaces index.js entirely with 5.2MB of heavily obfuscated JavaScript code using a ROT-character decoder and eval(), executing a hidden payload on require(). The benign first version established trust, then the malicious payload was pushed in a later update. The obfuscated payload's full behaviour cannot be determined from static analysis alone, but the size, structure, and delivery mechanism are consistent with credential harvesting or remote access payloads.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 09:19 AM
- analyzed
- Jun 25, 2026, 09:20 AM
Related advisories
- leo-config@1.1.1
- zenith-utils@12.0.14
- theme-color-picker@2.0.28
- pino-zod@1.0.121
- tailwindcss-effector@1.7.0
- assertcore@3.1.7
- chalk-ultra@12.0.3
- node-fetch-utils@1.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.