node-helper@1.5.4
Malicious code in node-helper (npm)
Analysis
node-helper@1.5.4 is a trojanized clone of the legitimate node-helper utility. The package declares a self-dependency on itself, and its main entry file (node-helper.js) contains an obfuscated payload that executes on require. The payload locates the npm binary and spawns a detached `npm install`, drops a VBScript (main.vbs) that runs a PowerShell command, and writes a package.json that installs axios, better-sqlite3, node-machine-id, socket[.]io-client, and (on Windows) @microsoft/office-js/office/dpap. It then spawns the VBScript detached. The implant targets Windows, uses DPAPI to decrypt stored credentials, fingerprints the host via node-machine-id, and establishes a socket[.]io-client command-and-control channel. The self-dependency causes the package to reinstall itself during installation.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 11:57 PM
- analyzed
- Sep 5, 2026, 11:58 PM
Related advisories
- kit-map-vim@1.0.0
- approval-guardian@1.0.8
- streak-metrics-math@1.0.1
- metrics-probe-9b4c@1.0.0
- env-config-f281@1.0.0
- @stellarshift/chain-metadata@1.0.1
- @stellarshift/evm-address-kit@1.0.1
- moidevy@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.