@divineubg/divine@1.1.2
Malicious code in @divineubg/divine (npm)
Analysis
The package is a browser game launcher that also opens a command-and-control channel over the public ntfy.sh pub/sub service. On load it generates a client id, POSTs a connection beacon to hxxps://ntfy[.]sh/dv-141u30-admin-status-<id>, and subscribes to hxxps://ntfy[.]sh/dv-141u30-admin-cmd-<id>/sse. Any message published to that topic with action "EVAL_CODE" is executed in the browser via eval() or new Function(), and the result is POSTed back to ntfy.sh. Because ntfy.sh topics are public and unauthenticated, any third party can publish commands to a victim's topic and run arbitrary JavaScript in the victim's browser. The topic names embed the literal prefix dv-141u30-admin-cmd- and dv-141u30-admin-status-.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 06:18 PM
- analyzed
- Aug 31, 2026, 06:18 PM
Related advisories
- tailwind-modernanimation@2.3.8
- zenntechinc-cli@1.6.4
- chai-as-mno@1.0.5
- fetch-page-assets@1.2.13
- @syncraft-labs/core@0.4.1
- chai-as-soul@2.3.6
- anhn-cli@1.1.4
- runtime-health@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.