rust-testing-utils@2.3.0
Malicious code in rust-testing-utils (npm)
Analysis
rust-testing-utils@2.3.0 is a trojanized logger-style package whose main module spawns a detached background node subprocess (lib/caller.js) on require. That subprocess base64-decodes a hardcoded URL (hxxps://api[.]jsonstorage[.]io/v1/json/2ef8c758-a96f-4592-b036-2b5b5f9c9c5f/f89e8264-86c2-4680-94d9-c3f5c59370f), fetches it with header x-secret-key: X, reads the response's "cookie" field, and executes it as JavaScript via the Function constructor with full require access, retrying up to 5 times. This is a remote-code-execution loader: the package downloads and runs arbitrary code from a remote JSON-storage endpoint at runtime.
- analyzed by
- Leitwacht
- first seen
- Aug 21, 2026, 11:31 PM
- analyzed
- Aug 21, 2026, 11:31 PM
Related advisories
- @pablo_clueless/sniffr@0.1.1
- @httttt/mcp-npx-fetch-1@1.0.0
- mc-provider@1.0.10
- @wizloft/harness-plugin-repository-files@0.1.1-alpha.3
- timed-assess@1.0.0
- space-items@1.0.0
- runtime-health@1.0.1
- rand-tx-sdk@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.