log-min@1.0.13
Malicious code in log-min (npm)
Analysis
log-min@1.0.13 impersonates a Theta-blockchain SDK but contains a postinstall hook that decrypts a payload from a bundled dependency and executes it in a detached background Node.js process. The postinstall runs node src, which imports an encrypted payload from the 'thedata' dependency, decrypts it using DES with a hardcoded password, and pipes the decrypted code into a spawned Node.js process via stdin. The package also reads a bundled des.db file for key material. The detached process runs independently of the parent, and the installation triggered network egress (DNS queries to external hosts). The package has no repository and no verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 06:10 PM
- analyzed
- Jul 30, 2026, 06:12 PM
Related advisories
- streak-metrics-core@1.0.0
- commonweb-flow@1.0.0
- test-flow-entire4@1.0.0
- voicemail@1.0.1
- fundraiserserv@28.0.0
- @daylightqc/date-fmt-lite@1.1.2
- system-performance-helper@1.0.1
- express-dever@5.1.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.