validator-string@13.15.36
Malicious code in validator-string (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
validator-string@13.15.36 is a combosquat of the legitimate validator package. It ships the real validator.js source code as camouflage but appends a heavily obfuscated JavaScript payload to index.js that executes on postinstall via the lifecycle hook. The obfuscated payload uses a Fisher-Yates shuffle-based string decoder and a large encoded blob that is decoded and executed at runtime. The package has no repository and no verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Jul 6, 2026, 07:46 PM
- analyzed
- Jul 6, 2026, 07:47 PM
Related advisories
- chai-secure@1.2.3
- nodepack-daemon@1.2.9
- next-locomotive-init@1.0.0
- @digiptf/common@99.99.99
- pinokio-redis@1.0.127
- chai-as-disarmed@3.2.3
- zredis-typed@1.0.127
- @bobfrankston/gcal@0.1.68
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.