LWA-2026-12079 MAL-2026-16169 ↗ confirmed malware

@biz44/id95-client@1.1.96

Malicious code in @biz44/id95-client (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process InjectionT1573 · Encrypted Channel

Analysis

Remote-code-execution dropper. Importing the package auto-spawns a detached background `node loader.js` process (PID persisted to a .pid file). loader.js fetches a remote JSON config from hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, base64-decodes the `code` field, and executes it via the Function constructor with full require/__dirname/__filename access — arbitrary remote code execution on the installer's machine. It also monkey-patches Node's Module.prototype.require to intercept child_process calls and force hidden windows on Windows. The remote payload is served at runtime, not shipped in the tarball.

analyzed by
Leitwacht
first seen
Sep 12, 2026, 05:41 PM
analyzed
Sep 12, 2026, 05:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.