js-soul@1.0.4
Malicious code in js-soul (npm)
Analysis
js-soul@1.0.4 executes a hidden payload at import time. On import, the module reads a file at ../../../../public/logo.ico (a path that escapes the package into the consuming project's public/ directory), decrypts it with the hardcoded DES password bf497c0b9cee, and spawns a detached node subprocess, piping the decrypted content to its stdin and unref()ing it so the payload runs as JavaScript in a background process that outlives the parent. The package's README falsely states it runs nothing on import. The encrypted payload file is not shipped in the tarball and is fetched from the host project at runtime.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 08:48 AM
- analyzed
- Aug 24, 2026, 08:49 AM
Related advisories
- mcq-session@1.0.4
- mutex-core@2.1.2
- sw-pluginer@1.1.0
- ai-pro-sdk@2.0.3
- theta-sdk-js@1.2.14
- chai-sdk@1.4.7
- luludawang-kit@0.0.1
- @marketfront/bannerpopup@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.