theta-sdk-js@1.2.14
Malicious code in theta-sdk-js (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or Information
Analysis
Package theta-sdk-js@1.2.14 is a trojanized clone of the Theta blockchain SDK. On import, it reads two encrypted payload files from a dependency (tchain-api) at node_modules/tchain-api/apps/docs/app/rsa.db and des.db, decrypts them using DES with a hardcoded password, and executes the decrypted code in two detached background node processes that outlive the parent process. The legitimate Theta SDK code is bundled as a disguise layer. The payload content is encrypted and delivered via the tchain-api dependency.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 12:59 PM
- analyzed
- Jul 10, 2026, 01:00 PM
Related advisories
- chai-sdk@1.4.7
- luludawang-kit@0.0.1
- @marketfront/bannerpopup@7.0.0
- autotel-edge@3.16.13
- autotel-cloudflare@2.18.16
- autotel-devtools@0.1.1
- autotel-mcp@0.1.14
- autotel-subscribers@10.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.