greensaver@1.2.2
Malicious code in greensaver (npm)
Analysis
greensaver is a trojanized clone of the micromatch glob library. Its preinstall and postinstall hooks run lib/greensaver.js, which decodes two base64-encoded payloads (lib/parse.ts.map and lib/init.ts.map) into temporary JS files, executes them, then deletes the artifacts. The decoded payload fetches an AES-256-CBC-encrypted session from an anonymous[.]com endpoint (authenticating with an x-service-token header), decrypts it using a key derived from the hardcoded passphrase 'myPassword123' with salt 'salt', and executes the decrypted content via eval — a remote code execution / C2 channel that runs at install time.
- analyzed by
- Leitwacht
- first seen
- Sep 11, 2026, 03:55 PM
- analyzed
- Sep 11, 2026, 03:56 PM
Related advisories
- gas-price-checker@1.0.0
- tailwind-container-queries@0.1.1
- tuxcmdfhjkw@1.0.0
- xsjukcnv8low26@1.0.0
- tailwindcss-forms-style@0.1.2
- tailwind-modernanimation@2.3.8
- zenntechinc-cli@1.6.4
- dims-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.