LWA-2026-6586 MAL-2026-10135 ↗ confirmed malware

theta-sdk-js@1.2.14

Malicious code in theta-sdk-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or Information

Analysis

Package theta-sdk-js@1.2.14 is a trojanized clone of the Theta blockchain SDK. On import, it reads two encrypted payload files from a dependency (tchain-api) at node_modules/tchain-api/apps/docs/app/rsa.db and des.db, decrypts them using DES with a hardcoded password, and executes the decrypted code in two detached background node processes that outlive the parent process. The legitimate Theta SDK code is bundled as a disguise layer. The payload content is encrypted and delivered via the tchain-api dependency.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 12:59 PM
analyzed
Jul 10, 2026, 01:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.