Hostile 100% javascript Download

swnwall 1.2.10

Remote code execution loader

“Special layout set module”

HTTPS GET contains response-data Function loaderRequire-enabled Function receives response data
SHA-25620882c9ff7067100b39625654c11c9568ec790fc1c2275ed8bfc85e2dddd6305

Also flagged by https://opensourcemalware.com/rss.xml (WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials), osm (This package implements a classic Contagious Interview / chai-max DPRK/Lazarus staged payload loader. The entrypoint (index.js) auto-initializes on import, spawning a detached background process via i…), osv (MAL-2026-16211: Malicious code in swnwall (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.