sigchain-js@1.0.1
Malicious code in sigchain-js (npm)
Analysis
sigchain-js@1.0.1 is a combosquat package impersonating the Theta blockchain SDK. On require(), it reads an encrypted payload from a bundled dependency file (node_modules/tchain-api/apps/docs/app/rsa.db), decrypts it with the hardcoded password "hydra", spawns a detached node process, and pipes the decrypted code to the child process's stdin for execution. The decrypted payload attempted outbound network communication at runtime.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 07:16 AM
- analyzed
- Jul 17, 2026, 07:17 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.