@biz44/runtime-utils@1.1.11
Malicious code in @biz44/runtime-utils (npm)
Analysis
Remote-code-execution dropper. Importing the package auto-runs an initializer that spawns a detached background `node loader.js` process (tracked via a .pid file). loader.js makes an HTTPS request to hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, reads a base64-encoded `code` field from the JSON response, decodes it, and executes it with full `require` access via the Function constructor, giving the remote server arbitrary code execution on the host. The package also monkey-patches Node's module loader to intercept child_process calls. The executed payload is served remotely and is not present in the tarball.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 04:02 AM
- analyzed
- Sep 14, 2026, 04:06 AM
Related advisories
- @biz44/process-runtime-utils@1.1.10
- @biz44/id99-client@1.1.100
- @biz44/id95-client@1.1.96
- id79-client@1.1.79
- @biz44/id12-client@1.1.13
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.