LWA-2026-11909 MAL-2026-15997 ↗ confirmed malware

node-helper@1.5.4

Malicious code in node-helper (npm)

T1059.007 · JavaScriptT1059.003 · Windows Command ShellT1059.001 · PowerShellT1555.004 · Windows Credential ManagerT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1027 · Obfuscated Files or InformationT1105 · Ingress Tool Transfer

Analysis

node-helper@1.5.4 is a trojanized clone of the legitimate node-helper utility. The package declares a self-dependency on itself, and its main entry file (node-helper.js) contains an obfuscated payload that executes on require. The payload locates the npm binary and spawns a detached `npm install`, drops a VBScript (main.vbs) that runs a PowerShell command, and writes a package.json that installs axios, better-sqlite3, node-machine-id, socket[.]io-client, and (on Windows) @microsoft/office-js/office/dpap. It then spawns the VBScript detached. The implant targets Windows, uses DPAPI to decrypt stored credentials, fingerprints the host via node-machine-id, and establishes a socket[.]io-client command-and-control channel. The self-dependency causes the package to reinstall itself during installation.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 11:57 PM
analyzed
Sep 5, 2026, 11:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.