LWA-2026-10073 MAL-2026-12004 ↗ confirmed malware

vitest-preview-pro@10.0.3

Malicious code in vitest-preview-pro (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1082 · System Information Discovery

Analysis

vitest-preview-pro@10.0.3 is a trojanized clone of the nodemailer package. Its preinstall hook (node lib/utils/index.js) spawns a detached background Node process running an obfuscated script at lib/utils/smtp-connection/index.js. That script uses a Function-constructor trick to obtain process and require, reads environment variables, and loads a large hex-encoded payload blob stored in lib/utils/smtp-connection/LICENSE (262KB, not a real license). The obfuscated loader constructs and executes further code from the embedded blob, making this a multi-stage dropper that runs on install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 05:47 PM
analyzed
Aug 4, 2026, 06:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.