Reddit
An npm typosquat of mathjs shipped an encrypted RAT that only decrypts when you pass it the right matrix
SafeDep disclosed on 2026-09-21 that npm package `mathmain`, an obfuscated copy of `mathjs`, carried a multi-stage loader whose decryption password is the JSON-stringified lower triangular factor of a matrix the caller passes in, so the payload stays inert and unanalysable until a victim uses the library normally. The malicious default was published 2026-09-17; the encrypted payload first appeared 2026-08-27. The decrypted implant uses Slack and Telegram channels plus Base Sepolia testnet blockchain command infrastructure, then writes and runs a `subwatcher` process under Node. Reported downloads of 605,157 for Sept 12-18 are unreliable because npm reported zero registry-wide downloads for Sept 17.
↳ Follow the thread