LWA-2026-6959 confirmed malware

topk-js@0.12.0

Malicious code in topk-js (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

topk-js@0.12.0 is a trojanized NAPI-RS native binding package. The package itself contains only standard NAPI-RS JavaScript loader code, but its optional dependencies include platform-specific native .node binary packages (topk-js-win32-arm64-msvc, topk-js-win32-ia32-msvc, topk-js-win32-x64-msvc) that are known malware. When the package is required in a Node.js application, the loader resolves and loads the malicious native binary for the target platform, executing the embedded payload. The package has no repository, no lifecycle hooks, and the malicious behaviour is delivered through the native binary rather than JavaScript.

analyzed by
Leitwacht
first seen
Jul 20, 2026, 03:32 PM
analyzed
Jul 20, 2026, 03:33 PM
weekly installs
73

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.