@rentwise/common@1.0.36
Malicious code in @rentwise/common (npm)
Analysis
@rentwise/common@1.0.36 ships a hidden C2 implant appended to build/index.js. On load, the package decodes an obfuscated payload that queries public Ethereum JSON-RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to read a transaction from a hardcoded address, derives two IPv4 addresses from the transaction's `to` field, and then spawns detached `node -e` processes that beacon to hxxp://<derived-ip>:443/0x/cls and /0x/ls, sending XOR-encoded payloads in an x-payload-b64 header. The implant establishes outbound connections to the derived C2 hosts over HTTP.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 07:35 AM
- analyzed
- Aug 5, 2026, 07:41 AM
Related advisories
- @nasdtickets/common@1.0.23
- bigops-backend@35.8.3
- bigops-informer@35.4.8
- stellarfixer@1.0.0
- terminal-kit-tslint-config@20.1.9
- tinkoff-statist-browser-typed-client-sme.rko.ta.ios.events@20.6.1
- invest-module-cookie@20.8.2
- hubert-react-query@20.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.