neverthrow-js@2.0.0
Malicious code in neverthrow-js (npm)
Analysis
The postinstall hook (dist/install.js) of neverthrow-js@2.0.0 fetches a remote payload and executes it. It constructs the URL hxxps://ecoferros[.]com/wp-content/plugins/elementor/modules/dev-tools/index[.]php?req=verify from obfuscated string fragments, downloads the response, base64-decodes it, and runs it via new Function with the require function passed in — executing arbitrary remote code at install time. The payload is served remotely rather than shipped in the package, and the hook is time-gated to activate after 2026-08-11 02:00:00 GMT. C2 host: ecoferros[.]com.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 02:55 AM
- analyzed
- Aug 10, 2026, 02:55 AM
Related advisories
- postcss-initial-provider@3.0.4
- godot-kit@1.0.1786316795
- fsbrowse@0.2.28
- cryptostock@1.0.0
- envpack-conf@1.0.1
- iconova-react@1.30.1
- @polymarkets/clob-client-v2@1.0.6
- @devmikets/hyperliquid-sdk@1.9.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.