id79-client@1.1.79
Malicious code in id79-client (npm)
Analysis
id79-client@1.1.79 is a remote-code-execution dropper. Importing the package auto-runs init.js, which spawns a detached background `node loader.js` process (persisted via a .pid file) that outlives the parent. loader.js makes an HTTPS GET to hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, reads a base64-encoded `code` field from the JSON response, decodes it, and executes it via the Function constructor with require/__dirname/__filename/module/exports in scope. The actual payload is served remotely from the npoint[.]io endpoint and is not shipped in the tarball, so the executed code is fully attacker-controlled at runtime.
- analyzed by
- Leitwacht
- first seen
- Sep 12, 2026, 05:50 PM
- analyzed
- Sep 12, 2026, 05:50 PM
Related advisories
- @biz44/id95-client@1.1.96
- @biz44/id12-client@1.1.13
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
- @solana-js/web3@1.91.3
- bigops-security@35.8.8
- delivery-ci-jira@35.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.