LWA-2026-6228 MAL-2026-6765 ↗ confirmed malware

@marketfront/bannerpopup@7.0.0

Malicious code in @marketfront/bannerpopup (npm)

T1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or InformationT1480 · Execution GuardrailsT1082 · System Information Discovery

Analysis

The postinstall script (scripts/postinstall.js) is a 164KB heavily obfuscated JavaScript payload using javascript-obfuscator with array shuffling, RC4/XOR string decryption, and anti-debugging checks that scan process.argv for profiler/debugger flags and process.env.NODE_OPTIONS. The package claims to be an internal authentication client but ships no actual library code (dist/index.js is a 76-byte stub pointing to a non-existent file), has zero dependencies, and the repository URL points to a non-existent domain. The obfuscated postinstall runs automatically on npm install.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 11:09 PM
analyzed
Jul 1, 2026, 11:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.