chain-analyze@1.0.2
Malicious code in chain-analyze (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File
Analysis
chain-analyze@1.0.2 is a trojanized Theta blockchain SDK. On require(), it reads an encrypted blob from node_modules/tchain-api/apps/docs/app/rsa.db, decrypts it with DES (password "hydra"), spawns a detached node subprocess, and pipes the decrypted code into its stdin for execution. The decryption key is imported from the dependency "chain-manager". The spawned process attempted network egress (DNS resolution observed). The package has no install script — the payload executes automatically when the module is loaded.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 10:41 AM
- analyzed
- Jul 28, 2026, 10:42 AM
Related advisories
- react-puller@1.0.0
- dateuuidv2@1.0.0
- block_package@1.0.0
- ai-pro-sdk@2.0.3
- dotnet-runtime-base@1.0.5
- txs-runner-lib@1.0.1
- express-route-engine@3.6.6
- testudo-pack@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.