vitest-cli-pro@10.0.7
Malicious code in vitest-cli-pro (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain
Analysis
vitest-cli-pro@10.0.7 is a trojanized clone of the nodemailer library. Its postinstall hook (node lib/utils/index.js) spawns a detached background process that runs lib/utils/smtp-connection/index.js, which performs an HTTP GET to hxxps://api[.]jsonbin[.]io/v3/b/6a62bc86da38895dfe879659 and executes the returned record.cookie value via new Function("require", ...) with full require access — a remote second-stage payload download-and-execute at install time. The C2/staging endpoint is api[.]jsonbin[.]io (bin 6a62bc86da38895dfe879659).
- analyzed by
- Leitwacht
- first seen
- Sep 1, 2026, 04:18 PM
- analyzed
- Sep 1, 2026, 04:18 PM
Related advisories
- xsjukcnv8low26@1.0.0
- @kentsuki/baileys@1.0.0
- tailwindcss-forms-style@0.1.2
- tailwind-minanimated@2.3.7
- tron-toolkit@1.0.1
- redis-cookie-server@1.0.0
- chai-as-spy@1.2.6
- autobahn-electron-probe@99.99.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.