encryptstringadmin@1.2.1
Malicious code in encryptstringadmin (npm)
Analysis
encryptstringadmin@1.2.1 is a heavily obfuscated JavaScript module that acts as a remote code loader. When the user calls its loadEncryptString() API, it fetches JavaScript from a remote CDN URL (domain obfuscated in the source) and executes it via new Function(), passing the crypto-js library as an argument. The remote payload can be changed at any time by the package maintainer without publishing a new version. The package has no repository, no install-time hooks, and no token-theft markers — the risk is the runtime fetch-and-execute pattern from an obfuscated remote endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 04:13 PM
- analyzed
- Jul 22, 2026, 04:15 PM
Related advisories
- vite-config-svg@1.1.7
- json-validator-utils@1.0.1
- ai-pro-sdk@2.0.3
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
- arb-kit@1.0.1
- @vite-tab/tabui@7.15.16
- node-fsagent@3.69.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.