malware npm

mathsbase

discovered 2026-09-18

mathjs clone (Deployment B) carrying the same loader/trigger with a different encrypted graph.js blob; Ethereum Sepolia smart-contract C2 sharing Alchemy key D2-TbkB2m05WXSnSDOCDI with Deployment A. SafeDep-confirmed. Sibling versions 1.0.0 (2026-08-26, no loader) and default 1.0.2 (2026-09-15, no loader, hid the malicious 1.0.1) were clean. Slack Workspace B bot token prefix xoxb-11307403103236-11289767127959-... (no schema indicator kind for Slack tokens).

Threat types

rat c2_agent typosquat

Malicious versions

  • 1.0.1 · 03e13cdedd9c33e6…

Campaigns

Indicators

Techniques

Read the full analysis →