node-request-utils@1.0.0
Malicious code in node-request-utils (npm)
Analysis
The postinstall hook runs a Windows-only dropper. On install it fingerprints the host (exits on CI environments, low CPU/RAM, or sandbox-related usernames/hostnames), then downloads a second-stage payload from hxxps://limbomail[.]com/api/attachment/l4TIRPOsaUxR[.]_603-vhKDRdgKl3RalN_TVUZYGPsJy2Y/all[.]js and writes it as winsvc.js into hidden directories under %APPDATA%\Microsoft\Windows (WinSxS\Backup, Themes, Caches) or %TEMP%\MicrosoftEdge. It installs persistence through a VBS launcher driven by a PowerShell encoded command that disables AMSI, sets the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, sets the UserInitMprLogonScript environment value, registers a scheduled task, and creates a Startup-folder shortcut, hiding the dropped files. It launches the payload detached via wscript.exe and re-checks the C2 host every 2 hours for updates.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 09:06 PM
- analyzed
- Aug 29, 2026, 09:06 PM
Related advisories
- sbirontime@1.0.0
- sbman@1.0.0
- sbironman@1.0.0
- biklitool@1.1.11
- @biklitime/biklimaster@1.1.6
- gpt-terminal-cli@1.0.0
- stellarfixer@1.0.0
- web3-token-helper@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.