@biz44/id10-client@1.1.11
Malicious code in @biz44/id10-client (npm)
Analysis
Remote-code-execution dropper. Importing the package auto-spawns a detached background 'node loader.js' process (PID persisted to a .pid file) that fetches a remote configuration from hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, base64-decodes the 'code' field, and executes it via the Function constructor with require/__dirname/__filename/module/exports supplied — so the actual payload is served remotely and never shipped in the tarball. The loader also monkey-patches Module.prototype.require to intercept child_process spawn/execSync calls. The remote endpoint is the command-and-control channel; the executed payload is fully attacker-controlled.
- analyzed by
- Leitwacht
- first seen
- Sep 12, 2026, 05:32 PM
- analyzed
- Sep 12, 2026, 05:35 PM
Related advisories
- @biz44/process-runtime-utils@1.1.10
- @biz44/runtime-utils@1.1.11
- @biz44/id99-client@1.1.100
- greensaver@1.2.2
- memfd-secret@1.0.0
- open-item-validator@1.0.2
- date-fns-formatter@1.3.8
- multicore-kit@1.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.