Tech & AI News
Hacker News

Why Does an NPM Math Library Need an Encrypted Loader?

The npm package mathmain contains a remote access implant that remains dormant until a specific mathjs solver equation provides the decryption key. Once triggered, the payload uses AES-GCM to decrypt malicious code, which then executes commands via public chat and blockchain networks. Identical malicious loaders also exist within the mathsbase and math-universe packages.