mchain-sdk@4.2.5
Malicious code in mchain-sdk (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter
Analysis
The postinstall hook (node ./src/core/index.js) reads a base64-encoded URL from src/core/config.js, fetches the content from hxxps://jsonkeeper[.]com/b/TW6AR, spawns a detached background node process, and pipes the fetched content into its stdin. This is a remote code stager: the pastebin URL serves a second-stage JavaScript payload that executes in a hidden child process that outlives the install.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 12:44 PM
- analyzed
- Jul 8, 2026, 12:44 PM
Related advisories
- @playerdata-internal/playerdata-core@9999.99.20
- testudo-pack@1.0.0
- configration@2.3.5
- express-mongo-limit@2.0.1
- express-guardian@1.4.1
- pinokio-redis@1.0.127
- agn-terminal@0.1.0
- zod-pino434@1.0.128
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.