LWA-2026-6873 MAL-2026-11146 ↗ confirmed malware

sigchain-js@1.0.1

Malicious code in sigchain-js (npm)

Analysis

sigchain-js@1.0.1 is a combosquat package impersonating the Theta blockchain SDK. On require(), it reads an encrypted payload from a bundled dependency file (node_modules/tchain-api/apps/docs/app/rsa.db), decrypts it with the hardcoded password "hydra", spawns a detached node process, and pipes the decrypted code to the child process's stdin for execution. The decrypted payload attempted outbound network communication at runtime.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 07:16 AM
analyzed
Jul 17, 2026, 07:17 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.