LWA-2026-6785 MAL-2026-10608 ↗ confirmed malware

chain-sdk-js@1.0.3

Malicious code in chain-sdk-js (npm)

Analysis

chain-sdk-js@1.0.3 impersonates the Theta Blockchain SDK. At require-time, the package reads DES-encrypted blobs (rsa.db, des.db) from a dependency (thedata), decrypts them with the hardcoded password "hydra" using CryptoJS.DES, then spawns a detached node child process and pipes the decrypted payload to its stdin for execution. The encrypted payload files are located at node_modules/thedata/apps/docs/app/rsa.db and node_modules/thedata/apps/docs/app/des.db. The decryption key "hydra" is hardcoded in the source. The package has no repository and claims author "Theta Labs" but is not affiliated with the legitimate Theta project.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 07:16 PM
analyzed
Jul 14, 2026, 07:18 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.