@biz44/id44-client@1.1.44
Malicious code in @biz44/id44-client (npm)
Analysis
@biz44/id44-client@1.1.44 is a remote-code-execution dropper. Importing the package immediately spawns a detached background `node loader.js` process (init.js, detached:true, unref'd, PID tracked in a .pid file). loader.js fetches a JSON document from hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, reads the `code` field, base64-decodes it, and executes it via `new Function("require","__dirname","__filename","module","exports", decodedCode)`, giving the remotely-served payload full Node.js require/module access. The executed payload is served remotely and is not present in the package, so its behaviour is fully attacker-controlled at runtime. The package auto-starts this on import with no opt-in.
- analyzed by
- Leitwacht
- first seen
- Sep 12, 2026, 05:36 PM
- analyzed
- Sep 12, 2026, 05:39 PM
Related advisories
- @biz44/process-runtime-utils@1.1.10
- @biz44/runtime-utils@1.1.11
- @biz44/id99-client@1.1.100
- tailwind-form-kit@0.6.2
- shaon-video-downloader@1.0.2
- node-helper@1.5.4
- date-fns-formatter@1.3.8
- tailwind-scrollbar-styles@4.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.