LWA-2026-12078 MAL-2026-16168 ↗ confirmed malware

@biz44/id79-client@1.1.80

Malicious code in @biz44/id79-client (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1574 · Hijack Execution Flow

Analysis

On import, the package auto-spawns a detached background `node loader.js` process (stdio ignored, PID persisted to a .pid file). The loader makes an HTTPS request to hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, base64-decodes a `code` field from the JSON response, and executes it via `new Function("require", ...)` with full module access — arbitrary remote code execution from a server-controlled payload. It also globally monkey-patches Node's `Module.prototype.require` to intercept `child_process` spawn/execSync calls made by the host application, forcing windowsHide and re-routing execSync through cmd.exe on Windows.

analyzed by
Leitwacht
first seen
Sep 12, 2026, 05:39 PM
analyzed
Sep 12, 2026, 05:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.