LWA-2026-7026 MAL-2026-11012 ↗ confirmed malware

encryptstringadmin@1.2.1

Malicious code in encryptstringadmin (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

encryptstringadmin@1.2.1 is a heavily obfuscated JavaScript module that acts as a remote code loader. When the user calls its loadEncryptString() API, it fetches JavaScript from a remote CDN URL (domain obfuscated in the source) and executes it via new Function(), passing the crypto-js library as an argument. The remote payload can be changed at any time by the package maintainer without publishing a new version. The package has no repository, no install-time hooks, and no token-theft markers — the risk is the runtime fetch-and-execute pattern from an obfuscated remote endpoint.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 04:13 PM
analyzed
Jul 22, 2026, 04:15 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.