@railone/image-utils@1.1.10
Malicious code in @railone/image-utils (npm)
Analysis
@railone/image-utils is a remote-code-execution dropper disguised as an image utility. Importing the package auto-starts a detached background process (node loader.js) that fetches a remote configuration from hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes a 'code' field from the response, and executes it via the Function constructor with require/__dirname/__filename/module/exports in scope. The actual payload is served remotely and is not shipped in the tarball, so the package can run arbitrary code on the installer's machine. The loader also patches child_process.spawn/execSync to force windowsHide on Windows. The package's stated purpose (image utilities) does not match this behaviour.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 05:18 PM
- analyzed
- Sep 14, 2026, 05:20 PM
Related advisories
- @biz44/runtime-utils@1.1.11
- id79-client@1.1.79
- @biz44/id95-client@1.1.96
- @biz44/id12-client@1.1.13
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
- @solana-js/web3@1.91.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.