News.Ycombinator Targeted Malware Campaign Using Malicious npm Packages
Article Content
- •Malicious npm package mathsbase mimics mathjs, achieving six million downloads quickly.
- •The malware activates only after solving a specific linear equation, making it highly targeted.
- •Payload communicates via Ethereum smart contracts and Slack, indicating sophisticated command-and-control methods.
Recent analysis revealed a targeted malware campaign utilizing malicious npm packages that mimic the popular mathjs library. The malicious package, named mathsbase, was downloaded over six million times within two days of its release, despite having no dependencies. The malware remains dormant until a specific mathematical equation is solved, which acts as a key to decrypt and execute a payload. This payload communicates with the attacker via a smart contract on the Ethereum Sepolia testnet and a Slack channel. The campaign has been active for at least six months, with detailed analysis uncovering the methods used to obfuscate the malicious code and the encryption techniques employed. Security researchers have provided insights into the loader's operation and potential indicators of compromise (IOCs). The situation is ongoing, with more investigations likely to follow.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Mathmain and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…