Why Does an NPM Math Library Need an Encrypted Loader?

Back to Blog Why Does an npm Math Library Need an Encrypted Loader? Security SafeDep Team • Sep 18, 2026 • 11 min read On this page 11 sections On this page
We found a remote access implant hidden inside [email protected] , an npm package that copies the popular mathjs library. The malicious code ships encrypted. It stays dormant until a program solves a specific equation with the library. That equation is the key. When the key matches, the package decrypts a payload and runs it. The payload takes commands from the attacker and runs them on the host. It uses a public chat service and a blockchain network for its command channel. This post shows how we found the loader, how we decrypted it, what the payload does, and the indicators you can use to find it.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in