LWA-2026-5971 MAL-2026-11089 ↗ confirmed malware

txs-builder@1.0.6

Malicious code in txs-builder (npm)

T1059.007 · JavaScriptT1059.006 · PythonT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1027 · Obfuscated Files or Information

Analysis

txs-builder@1.0.6 is a trojanized package disguised as an ecommerce transaction-data generator. It ships a base64-encoded payload in test_address_list.js (with 0x-prefix obfuscation) that is decoded and eval'd when the package's exported getTransactions() function is called. The decoded code downloads a remote script from hxxps://kb4h5c83t[.]userdom[.]com/inform[.]php, writes it to the system's temporary directory as tmp_20260521, and executes it as a detached Python process. The final remote payload is fetched at runtime, making this a multi-stage downloader trojan.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 12:39 PM
analyzed
Jun 25, 2026, 12:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.