modsync@5.0.2
Malicious code in modsync (npm)
Analysis
modsync@5.0.2 is a trojanized clone of the pino logger that ships a 4.1MB obfuscated lib/config.js. When the module is loaded, the obfuscated code collects the host's hostname, OS version, platform, and username and POSTs them as JSON to 167[.]88[.]167[.]54:8087 at /api/log and /api/notify, and uploads a sysinfo.txt file (containing host, OS, username, platform, timestamp) via multipart/form-data to 167[.]88[.]167[.]54:8085 at /upload. The C2 requests carry a per-install Validation HMAC header and a numeric userkey. The package exfiltrates system information from the machine that installs it.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 04:51 AM
- analyzed
- Aug 19, 2026, 04:53 AM
Related advisories
- pump-fun-skills@20.1.1
- carbon-monorepo@20.1.1
- pump-segments-sdk@20.1.1
- chai-as-gateway@7.1.5
- react-dom-helpers@3.3.3
- bqq1@1.0.0
- @library-dev-team/data-sanitizer@1.3.0
- @oyo_tech/oyochat_user@100.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.