Why Does an npm Math Library Need an Encrypted Loader?
Summary
SafeDep analyzes an encrypted loader hidden in an npm package named mathmain that decrypts and executes a payload when triggered by a password derived from LU decomposition. The writeup details the loader workflow, decryption process, payload capabilities, and indicators of compromise, including C2 channels via Slack and Telegram, plus an investigation timeline. It highlights supply-chain risk in the JavaScript ecosystem and provides actionable detection guidance for security teams and developers.