LWA-2026-7183 MAL-2026-11133 ↗ confirmed malware

chain-analyze@1.0.2

Malicious code in chain-analyze (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

chain-analyze@1.0.2 is a trojanized Theta blockchain SDK. On require(), it reads an encrypted blob from node_modules/tchain-api/apps/docs/app/rsa.db, decrypts it with DES (password "hydra"), spawns a detached node subprocess, and pipes the decrypted code into its stdin for execution. The decryption key is imported from the dependency "chain-manager". The spawned process attempted network egress (DNS resolution observed). The package has no install script — the payload executes automatically when the module is loaded.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 10:41 AM
analyzed
Jul 28, 2026, 10:42 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.