LWA-2026-11912 MAL-2026-15995 ↗ confirmed malware

multicore-kit@1.1.5

Malicious code in multicore-kit (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

multicore-kit@1.1.5 is a multi-stage dropper disguised as an array-utility library. Requiring the package executes an obfuscated payload that creates a hidden directory under the OS temp dir (node_modules), writes a second-stage obfuscated script to a hidden .vs_cache file, and writes a package.json that pulls in axios, better-sqlite3, node-machine-id, socket[.]io-client, and (on Windows) @azure/msal-node/dpapi. It then spawns node (or cmd.exe on Windows) to run the second-stage script, re-launching it on exit. The dependency set indicates host fingerprinting (node-machine-id), a command/control channel (socket[.]io-client/axios), and Windows DPAPI credential decryption (msal-node/dpapi). The package's stated purpose (array flattening) is unrelated to this behaviour.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 11:19 PM
analyzed
Sep 5, 2026, 11:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.