@vboxdev/common@1.0.73
Malicious code in @vboxdev/common (npm)
Analysis
@vboxdev/common@1.0.73 ships an obfuscated eval(atob(...)) payload appended to build/index.js. On load it queries public Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to locate the latest block containing a transaction from hardcoded address 0xa3322e5f33d3311d3308e6f0121063e9aDC2490Ef1a. It reads the transaction's `to` field, whose first 4 bytes encode an IP address, then spawns a detached node process that beacons to hxxp://<ip>:80 and hxxp://<ip>:443 with XOR-encoded payloads — a blockchain dead-drop command-and-control channel whose C2 IP is derived on-chain. The package also ships a live Firebase service-account private key in build/services/serviceAccountKey.json.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 10:02 AM
- analyzed
- Aug 5, 2026, 10:09 AM
Related advisories
- streak-calc-metrics@1.0.0
- tailwind-hide-scrollbar@2.1.5
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- @nasdtickets/common@1.0.23
- tailwindcss-scrollbar-hide@2.2.6
- @tuluax/errb@3.0.1
- webdev-conf@5.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.