LWA-2026-12082 MAL-2026-16173 ↗ confirmed malware

id79-client@1.1.79

Malicious code in id79-client (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

id79-client@1.1.79 is a remote-code-execution dropper. Importing the package auto-runs init.js, which spawns a detached background `node loader.js` process (persisted via a .pid file) that outlives the parent. loader.js makes an HTTPS GET to hxxps://api[.]npoint[.]io/24c12c4b66a29747764f, reads a base64-encoded `code` field from the JSON response, decodes it, and executes it via the Function constructor with require/__dirname/__filename/module/exports in scope. The actual payload is served remotely from the npoint[.]io endpoint and is not shipped in the tarball, so the executed code is fully attacker-controlled at runtime.

analyzed by
Leitwacht
first seen
Sep 12, 2026, 05:50 PM
analyzed
Sep 12, 2026, 05:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.