punypump@1.2.4
Malicious code in punypump (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1140 · Deobfuscate/Decode Files or Information
Analysis
On require, the package's library.js fetches an encrypted payload from the JSON-paste host hxxps://www[.]jsonkeeper[.]com/b/V6NBX (request carries a hardcoded x-secret-key header), decrypts it with AES-256-CBC using a key derived via scrypt from a hardcoded credential, and executes the decrypted content with eval. The remote content is fully attacker-controlled, so any install or require of the package runs arbitrary code supplied by the remote host.
- analyzed by
- Leitwacht
- first seen
- Sep 8, 2026, 10:09 AM
- analyzed
- Sep 8, 2026, 10:11 AM
Related advisories
- discord-mfa@3.0.0
- js-soul@1.0.4
- mcq-session@1.0.4
- sw-pluginer@1.1.0
- tailwind-custom-forms@0.5.2
- theta-sdk-js@1.2.14
- luludawang-kit@0.0.1
- jsf-utils@1.3.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.