LWA-2026-11943 MAL-2026-16048 ↗ confirmed malware

punypump@1.2.4

Malicious code in punypump (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1140 · Deobfuscate/Decode Files or Information

Analysis

On require, the package's library.js fetches an encrypted payload from the JSON-paste host hxxps://www[.]jsonkeeper[.]com/b/V6NBX (request carries a hardcoded x-secret-key header), decrypts it with AES-256-CBC using a key derived via scrypt from a hardcoded credential, and executes the decrypted content with eval. The remote content is fully attacker-controlled, so any install or require of the package runs arbitrary code supplied by the remote host.

analyzed by
Leitwacht
first seen
Sep 8, 2026, 10:09 AM
analyzed
Sep 8, 2026, 10:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.