Tech News
← Home  ·  All topics

Encrypted Malware Loader

1 GoKawiil brief on this topic

Fake mathjs npm package hides encrypted backdoor triggered by equation solving

Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.