@biz44/process-runtime-utils@1.1.10
Malicious code in @biz44/process-runtime-utils (npm)
Analysis
The package auto-executes on import: index.js spawns a detached background `node loader.js` process (PID persisted to a .pid file) that survives the parent. loader.js makes an HTTPS request to hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes the `code` field from the JSON response, and executes it via the Function constructor with require/__dirname/__filename/module/exports provided — a remote-code-execution dropper whose payload is served remotely rather than shipped in the tarball. loader.js also monkey-patches Node's Module.prototype.require to intercept child_process spawn/execSync calls. The remote payload is fetched and executed at runtime, so its full behaviour is determined by the C2 endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 05:17 AM
- analyzed
- Sep 14, 2026, 05:20 AM
Related advisories
- @biz44/runtime-utils@1.1.11
- @biz44/id99-client@1.1.100
- @biz44/id95-client@1.1.96
- hydration-ui-pkg@1.0.0
- space-items@1.0.0
- streak-map-kit@1.0.0
- dolyame-ui-inputtime@35.8.1
- dolyame-boxy-fonts@35.4.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.