Why Does an npm Math Library Need an Encrypted Loader?
Summary
SafeDep's article analyzes a supply-chain style attack where an npm package hides an encrypted loader that decrypts and executes a payload upon a trigger derived from a LU decomposition of a matrix. The piece details the loader, encryption/decryption workflow, staged payloads, indicators of compromise, and an investigation timeline, highlighting supply-chain risks and defender-focused IOC guidance.