validator-stringnpm
Advisory published Updated
validator-string is a confirmed malicious npm package (MAL-2026-10109) that typosquats a legitimate package to trick installs (malicious version 13.15.36). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in validator-string (npm)
What this malware does
Package name validator-string impersonates the widely-used npm package validator and copies its README, homepage, and API surface. package.json declares scripts.postinstall: node index.js, and main resolves to the same index.js, so the trailing obfuscated block runs both on npm install and on every require('validator-string'). The appended code uses a custom multi-stage character-shuffle routine to reconstruct the identifiers require, module, __dirname, __filename, undefined, and constructor, then hoists require/module/__dirname/__filename onto global so the decoded body has full Node.js capability. It recovers the string Function from constructor, invokes Function(argNames, decodedBody) on a large opaque encoded blob, and calls the resulting function unconditionally (Lpe(2163)). This is dynamic code construction from an obfuscated payload executed automatically on install and on load — installer-side remote/opaque code execution with full Node privileges. The typosquat name, cloned metadata, obfuscation of core Node identifiers, and auto-execution at two separate lifecycle points are collectively unambiguous.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for validator-string (version 13.15.36).
If you installed it — respond
validator-string is a typosquat — you almost certainly intended a legitimately-named package. Remove validator-string, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If validator-string was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks validator-string-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.