multicore-kit@1.1.5
Malicious code in multicore-kit (npm)
Analysis
multicore-kit@1.1.5 is a multi-stage dropper disguised as an array-utility library. Requiring the package executes an obfuscated payload that creates a hidden directory under the OS temp dir (node_modules), writes a second-stage obfuscated script to a hidden .vs_cache file, and writes a package.json that pulls in axios, better-sqlite3, node-machine-id, socket[.]io-client, and (on Windows) @azure/msal-node/dpapi. It then spawns node (or cmd.exe on Windows) to run the second-stage script, re-launching it on exit. The dependency set indicates host fingerprinting (node-machine-id), a command/control channel (socket[.]io-client/axios), and Windows DPAPI credential decryption (msal-node/dpapi). The package's stated purpose (array flattening) is unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 11:19 PM
- analyzed
- Sep 5, 2026, 11:20 PM
Related advisories
- jwt-logger@2.1.9
- eth-query-utils@1.0.0
- eth-lib-helpers@1.0.0
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
- afhmxiewpsf@1.0.0
- 2nestjs@0.0.1
- 1nestjs@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.