ranux-cloud@1.0.0
Malicious code in ranux-cloud (npm)
Analysis
ranux-cloud@1.0.0 ships a single obfuscated entry file (index.js, ~3.1MB) that acts as a loader. On require, it imports node:crypto, constructs a decipher, decrypts a large embedded encrypted blob, and executes the decrypted payload, then wipes the key/IV/auth-tag buffers from memory. The code is obfuscated with a large encoded string array and custom decoder, so the payload's behaviour is not visible statically. No network endpoint was observed in the static analysis; the package's stated purpose (a network socket/protocol engine) is not substantiated by any readable implementation.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 10:45 AM
- analyzed
- Aug 15, 2026, 10:48 AM
Related advisories
- @finaxis/common-js@0.3.3
- twcvhjlksdmx@1.0.0
- vitest-preview-pro@10.0.7
- @coralxyz/anchor@0.30.2
- hardhat-cap@2.21.1
- dolyame-ui-draghoc@35.8.1
- dolyame-ui-tablemobile@35.8.1
- txrand@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.