neverthrow-core@1.1.2
Malicious code in neverthrow-core (npm)
Analysis
neverthrow-core is a combosquat clone of the neverthrow Result library that injects a preinstall hook (node -e "require('./dist/index.cjs.js').bcryptInstall()"). The hook downloads a tarball from a Dropbox shared link (dropbox[.]com/scl/fi/l5tqqo3mxuemus9cqpbqe/bcrypt-all-platforms.tar.gz, with rlkey/st/dl query parameters) and executes a base64-decoded payload as JavaScript via the Function constructor (new Function("rqr", binary); binary(require)()). The payload is served remotely rather than shipped in the tarball, making this a remote-code-execution dropper. An obfuscated XOR-encoded deadline token is used to force the Dropbox mirror after a hidden date. The genuine neverthrow package has no bcrypt dependency and no preinstall hook.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 01:12 PM
- analyzed
- Aug 11, 2026, 01:13 PM
Related advisories
- kit-vim-map@1.0.0
- vexium-kit@2.0.2
- dayjs-advanced@1.2.0
- postcss-initial-provider@3.0.4
- godot-kit@1.0.1786316795
- fsbrowse@0.2.28
- cryptostock@1.0.0
- envpack-conf@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.