chain-sdk-js@1.0.3
Malicious code in chain-sdk-js (npm)
Analysis
chain-sdk-js@1.0.3 impersonates the Theta Blockchain SDK. At require-time, the package reads DES-encrypted blobs (rsa.db, des.db) from a dependency (thedata), decrypts them with the hardcoded password "hydra" using CryptoJS.DES, then spawns a detached node child process and pipes the decrypted payload to its stdin for execution. The encrypted payload files are located at node_modules/thedata/apps/docs/app/rsa.db and node_modules/thedata/apps/docs/app/des.db. The decryption key "hydra" is hardcoded in the source. The package has no repository and claims author "Theta Labs" but is not affiliated with the legitimate Theta project.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 07:16 PM
- analyzed
- Jul 14, 2026, 07:18 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.