LWA-2026-12094 MAL-2026-16172 ↗ confirmed malware

@biz44/runtime-utils@1.1.11

Malicious code in @biz44/runtime-utils (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

Remote-code-execution dropper. Importing the package auto-runs an initializer that spawns a detached background `node loader.js` process (tracked via a .pid file). loader.js makes an HTTPS request to hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, reads a base64-encoded `code` field from the JSON response, decodes it, and executes it with full `require` access via the Function constructor, giving the remote server arbitrary code execution on the host. The package also monkey-patches Node's module loader to intercept child_process calls. The executed payload is served remotely and is not present in the tarball.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 04:02 AM
analyzed
Sep 14, 2026, 04:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.