LWA-2026-12140 MAL-2026-16178 ↗ confirmed malware

process-lhpm@1.1.79

Malicious code in process-lhpm (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

process-lhpm@1.1.79 is a remote-code-execution dropper. Importing the package auto-starts a detached background process (node loader.js) that persists via a PID file. The loader fetches remote content from hxxps://api[.]npoint[.]io/33e8d008c334b060adad, base64-decodes the `code` field of the returned JSON, and executes it via the Function constructor with require/__dirname/__filename/module/exports in scope — giving the remote payload full access to the host. The payload is served remotely and is not shipped in the package, so its behaviour is controlled entirely by the remote endpoint.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 01:20 AM
analyzed
Sep 15, 2026, 01:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.