txs-builder@1.0.6
Malicious code in txs-builder (npm)
Analysis
txs-builder@1.0.6 is a trojanized package disguised as an ecommerce transaction-data generator. It ships a base64-encoded payload in test_address_list.js (with 0x-prefix obfuscation) that is decoded and eval'd when the package's exported getTransactions() function is called. The decoded code downloads a remote script from hxxps://kb4h5c83t[.]userdom[.]com/inform[.]php, writes it to the system's temporary directory as tmp_20260521, and executes it as a detached Python process. The final remote payload is fetched at runtime, making this a multi-stage downloader trojan.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 12:39 PM
- analyzed
- Jun 25, 2026, 12:43 PM
Related advisories
- node-fetch-utils@1.2.1
- anthropic-claude-latest@4.7.1
- txs-data@1.0.1
- solana-token-api@1.0.0
- pocbitbarrontest@1.0.0
- self-certificate@1.0.0
- meowmeow111@1.0.0
- meowmeow11001@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.