LWA-2026-12102 MAL-2026-16171 ↗ confirmed malware

@biz44/process-runtime-utils@1.1.10

Malicious code in @biz44/process-runtime-utils (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1543 · Create or Modify System Process

Analysis

The package auto-executes on import: index.js spawns a detached background `node loader.js` process (PID persisted to a .pid file) that survives the parent. loader.js makes an HTTPS request to hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes the `code` field from the JSON response, and executes it via the Function constructor with require/__dirname/__filename/module/exports provided — a remote-code-execution dropper whose payload is served remotely rather than shipped in the tarball. loader.js also monkey-patches Node's Module.prototype.require to intercept child_process spawn/execSync calls. The remote payload is fetched and executed at runtime, so its full behaviour is determined by the C2 endpoint.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 05:17 AM
analyzed
Sep 14, 2026, 05:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.