LWA-2026-6463 MAL-2026-10012 ↗ confirmed malware

mchain-sdk@4.2.5

Malicious code in mchain-sdk (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

The postinstall hook (node ./src/core/index.js) reads a base64-encoded URL from src/core/config.js, fetches the content from hxxps://jsonkeeper[.]com/b/TW6AR, spawns a detached background node process, and pipes the fetched content into its stdin. This is a remote code stager: the pastebin URL serves a second-stage JavaScript payload that executes in a hidden child process that outlives the install.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 12:44 PM
analyzed
Jul 8, 2026, 12:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.