devpack-conf@5.0.0
Malicious code in devpack-conf (npm)
Analysis
devpack-conf@5.0.0 is a trojanized config-reading package whose index.js appends an eval(atob(...)) payload. On load it queries public Ethereum JSON-RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to locate a transaction from address 0x8a3322e5f3d311d30e6f0121063e9aDC24d90e5a, extracts the transaction's `to` field, and splits it into two IPv4 addresses. It then spawns a detached background node process that connects to those addresses on ports 80/443 and sends XOR-encoded requests to the paths /0x/cls and /0x/ls, retrieving and executing second-stage commands. The C2 infrastructure is rotated via the blockchain, so the beacon destinations change with each new transaction from the controlling address.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 08:36 AM
- analyzed
- Aug 5, 2026, 08:39 AM
Related advisories
- tailwind-hide-scrollbar@2.1.5
- @rentwise/common@1.0.36
- @nasdtickets/common@1.0.23
- bigops-backend@35.8.3
- bigops-informer@35.4.8
- stellarfixer@1.0.0
- terminal-kit-tslint-config@20.1.9
- tinkoff-statist-browser-typed-client-sme.rko.ta.ios.events@20.6.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.