hexo-shoka-swiper@0.1.10
Malicious code in hexo-shoka-swiper (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File
Analysis
hexo-shoka-swiper@0.1.10 is a trojanized hexo plugin. During npm install, a binding.gyp file executes an obfuscated 5.3MB JavaScript payload via the node-gyp build system's command-injection syntax, with all output suppressed to stderr/stdout to avoid detection. The genuine plugin code is kept intact in ./lib/ as camouflage. The 5.3MB index.js is a single heavily-obfuscated eval statement with no legitimate module code — a ROT-cipher character-code decoder concealing the actual payload.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 09:19 AM
- analyzed
- Jun 25, 2026, 09:22 AM
- weekly installs
- 164
Related advisories
- proto-bin@2.3.3
- weavedb-node-client@0.45.3
- @httpactions/encode-url@1.0.0
- ui-core-system@1.0.3
- toast-react-slider@1.0.0
- stylelint-standard@1.2.0
- strutil-kit@1.0.0
- str-master@1.0.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.