vitest-chalk-pro@10.0.7
Malicious code in vitest-chalk-pro (npm)
Analysis
vitest-chalk-pro@10.0.7 is a trojanized clone of the nodemailer library with an injected remote-code-execution payload. Its postinstall hook (node lib/utils/index.js) spawns a detached background child process that runs lib/utils/smtp-connection/index.js, which fetches a payload from hxxps://api[.]jsonbin[.]io/v3/b/6a62bc86da38895dfe879659 and executes the returned record.cookie field via the Function constructor with require in scope, giving the remote payload full access to the Node.js runtime. The fetched code is attacker-controlled and runs on every install.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 04:47 PM
- analyzed
- Aug 27, 2026, 04:50 PM
Related advisories
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
- selfsigned-certificate@1.0.0
- tailwindcss-form-styles@0.5.15
- tailwindcss-3d-animate@1.2.2
- htps-provider@1.0.11
- js-tokens-array@1.0.0
- date-fns-sync@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.