LWA-2026-12129 MAL-2026-16261 ↗ confirmed malware

@railone/image-utils@1.1.10

Malicious code in @railone/image-utils (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

@railone/image-utils is a remote-code-execution dropper disguised as an image utility. Importing the package auto-starts a detached background process (node loader.js) that fetches a remote configuration from hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes a 'code' field from the response, and executes it via the Function constructor with require/__dirname/__filename/module/exports in scope. The actual payload is served remotely and is not shipped in the tarball, so the package can run arbitrary code on the installer's machine. The loader also patches child_process.spawn/execSync to force windowsHide on Windows. The package's stated purpose (image utilities) does not match this behaviour.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 05:18 PM
analyzed
Sep 14, 2026, 05:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.