A malicious npm package impersonating mathjs contains an encrypted remote access implant that activates when a specific equation is solved. The loader uses the matrix data as a decryption key to reveal and execute a payload that accepts attacker commands via chat services and blockchain networks. Similar implants were found in two other copycat packages on npm.