process-lhpm@1.1.79
Malicious code in process-lhpm (npm)
Analysis
process-lhpm@1.1.79 is a remote-code-execution dropper. Importing the package auto-starts a detached background process (node loader.js) that persists via a PID file. The loader fetches remote content from hxxps://api[.]npoint[.]io/33e8d008c334b060adad, base64-decodes the `code` field of the returned JSON, and executes it via the Function constructor with require/__dirname/__filename/module/exports in scope — giving the remote payload full access to the host. The payload is served remotely and is not shipped in the package, so its behaviour is controlled entirely by the remote endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 01:20 AM
- analyzed
- Sep 15, 2026, 01:20 AM
Related advisories
- @railone/image-utils@1.1.10
- @biz44/runtime-utils@1.1.11
- id79-client@1.1.79
- @biz44/id95-client@1.1.96
- @biz44/id12-client@1.1.13
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.