LWA-2026-10100 MAL-2026-12330 ↗ confirmed malware

@vboxdev/common@1.0.73

Malicious code in @vboxdev/common (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool TransferT1102 · Web Service

Analysis

@vboxdev/common@1.0.73 ships an obfuscated eval(atob(...)) payload appended to build/index.js. On load it queries public Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to locate the latest block containing a transaction from hardcoded address 0xa3322e5f33d3311d3308e6f0121063e9aDC2490Ef1a. It reads the transaction's `to` field, whose first 4 bytes encode an IP address, then spawns a detached node process that beacons to hxxp://<ip>:80 and hxxp://<ip>:443 with XOR-encoded payloads — a blockchain dead-drop command-and-control channel whose C2 IP is derived on-chain. The package also ships a live Firebase service-account private key in build/services/serviceAccountKey.json.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 10:02 AM
analyzed
Aug 5, 2026, 10:09 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.