dayjs-advanced@1.2.0
Malicious code in dayjs-advanced (npm)
Analysis
dayjs-advanced is a combosquat of the dayjs date library that ships a multi-stage dropper in esm/utils.js. On import it hardcodes the Ethereum wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a and queries public Ethereum RPC endpoints (1rpc[.]io, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) and eth[.]blockscout[.]com/api to locate that wallet's transactions; the recipient address of the found transaction encodes two C2 IP addresses. It then fetches XOR-encrypted second-stage payloads from hxxp://<ip>:443/0x/cls and hxxp://<ip>:443/0x/ls, decrypts them, and executes them both via eval() and by spawning a detached, hidden `node -e` process (stdio ignored, windowsHide set). The payload also probes for a local canary domain during execution. The C2 channel is discovered dynamically from the blockchain, so the destination IPs are not fixed in the package.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 03:10 PM
- analyzed
- Aug 10, 2026, 03:11 PM
Related advisories
- postcss-initial-provider@3.0.4
- godot-kit@1.0.1786316795
- fsbrowse@0.2.28
- cryptostock@1.0.0
- envpack-conf@1.0.1
- iconova-react@1.30.1
- kit-map-streak@1.0.0
- @kolbo/mcp@1.57.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.