Skip to content
Targeted Malware Campaign Using Malicious npm Packages

Targeted Malware Campaign Using Malicious npm Packages

First seen 21 Sep 2026, 21:12 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 20:29 UTC
  • Malicious npm package mathsbase mimics mathjs, achieving six million downloads quickly.
  • The malware activates only after solving a specific linear equation, making it highly targeted.
  • Payload communicates via Ethereum smart contracts and Slack, indicating sophisticated command-and-control methods.

Recent analysis revealed a targeted malware campaign utilizing malicious npm packages that mimic the popular mathjs library. The malicious package, named mathsbase, was downloaded over six million times within two days of its release, despite having no dependencies. The malware remains dormant until a specific mathematical equation is solved, which acts as a key to decrypt and execute a payload. This payload communicates with the attacker via a smart contract on the Ethereum Sepolia testnet and a Slack channel. The campaign has been active for at least six months, with detailed analysis uncovering the methods used to obfuscate the malicious code and the encryption techniques employed. Security researchers have provided insights into the loader's operation and potential indicators of compromise (IOCs). The situation is ongoing, with more investigations likely to follow.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-17
SafeDep analysis of mathsbase initiated
Researchers began analyzing the suspicious npm package mathsbase, which appeared to replicate mathjs.
News.Ycombinator
2026-09-20
Discovery of malicious loader
The loader was found to decrypt and execute a payload based on solving a specific equation.
research.jfrog.com
2026-09-21
Public disclosure of findings
Research articles detailing the malware campaign were published, highlighting its methods and implications.
research.jfrog.com

More articles in this cluster (2)

Following this threat?

Track Mathmain and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed