LWA-2026-12076 MAL-2026-16166 ↗ confirmed malware

@biz44/id12-client@1.1.13

Malicious code in @biz44/id12-client (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1055 · Process Injection

Analysis

@biz44/id12-client@1.1.13 is a remote-code-execution dropper. Importing the package auto-spawns a detached background `node loader.js` process (persisted via a .pid file). loader.js fetches a JSON payload from hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, base64-decodes the `code` field, and executes it with full require/module access via the Function constructor, giving the remote server arbitrary code execution on the host. It also monkey-patches Module.prototype.require to intercept child_process calls. The malicious second stage is served remotely from npoint[.]io rather than shipped in the package.

analyzed by
Leitwacht
first seen
Sep 12, 2026, 05:34 PM
analyzed
Sep 12, 2026, 05:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.