LWA-2026-5962 MAL-2026-6492 ↗ confirmed malware

hexo-shoka-swiper@0.1.10

Malicious code in hexo-shoka-swiper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File

Analysis

hexo-shoka-swiper@0.1.10 is a trojanized hexo plugin. During npm install, a binding.gyp file executes an obfuscated 5.3MB JavaScript payload via the node-gyp build system's command-injection syntax, with all output suppressed to stderr/stdout to avoid detection. The genuine plugin code is kept intact in ./lib/ as camouflage. The 5.3MB index.js is a single heavily-obfuscated eval statement with no legitimate module code — a ROT-cipher character-code decoder concealing the actual payload.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 09:19 AM
analyzed
Jun 25, 2026, 09:22 AM
weekly installs
164

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.