vitest-preview-pro@10.0.7
Malicious code in vitest-preview-pro (npm)
Analysis
A package named vitest-preview-pro (a combosquat of the real vitest-preview) that is actually a trojanized nodemailer clone. Its postinstall hook (node lib/utils/index.js) spawns a detached node child process running lib/utils/smtp-connection/index.js, an obfuscated script that fetches remote code from two jsonbin[.]io buckets (hxxps://api[.]jsonbin[.]io/v3/b/6a709899da38895dfeb3bc72 and hxxps://api[.]jsonbin[.]io/v3/b/698b7468d0ea881f40b029b3) and executes the returned payload via new Function('require', data.record.cookie)(require). This is remote code fetch-and-execute at install time, with the second-stage payload fully attacker-controlled.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 10:55 AM
- analyzed
- Aug 7, 2026, 09:45 PM
Related advisories
- vitest-preview-pro@10.0.3 same package
- sme-rko-finance-front-operations-domain@35.8.1
- sme-rko-finance-front-operations-feed-models@35.8.1
- sme-rko-finance-front-operations-feed-impl@35.8.1
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- sme-rko-finance-front-operations-notifications-models@35.8.1
- sme-rko-finance-front-operations-holding-domain@35.8.1
- sme-rko-finance-front-operations-income@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.