@biz44/id99-client@1.1.100
Malicious code in @biz44/id99-client (npm)
Analysis
@biz44/id99-client@1.1.100 executes remote code on import. Importing the package (index.js) automatically spawns a detached background `node loader.js` process (PID persisted to a .pid file). loader.js performs an HTTPS GET to hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, reads the `code` field from the returned JSON, base64-decodes it, and executes the decoded string via the Function constructor with require/__dirname/__filename/module/exports in scope — a remote-code-execution dropper whose payload is served remotely rather than shipped in the tarball. It also monkey-patches Module.prototype.require to intercept child_process spawn/execSync calls. The remote endpoint fully controls what code runs on the host.
- analyzed by
- Leitwacht
- first seen
- Sep 12, 2026, 05:42 PM
- analyzed
- Sep 12, 2026, 05:45 PM
Related advisories
- @biz44/process-runtime-utils@1.1.10
- @biz44/runtime-utils@1.1.11
- @biz44/id95-client@1.1.96
- grafeno-pix@1.0.0
- grafeno-utils@1.0.0
- hydration-ui-dlx@1.0.0
- hydration-ui-dim@1.0.0
- hydration-dim-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.