engin1@1.3.99
Malicious code in engin1 (npm)
Analysis
engin1@1.3.99 executes remote code on import. The package's index.js auto-imports init.js, which spawns a detached `node loader.js` child process. loader.js makes an HTTPS request to hxxps://api[.]npoint[.]io/24c25d5f5fcbb0992a4f, reads the `code` field from the JSON response, base64-decodes it, and executes it via the Function constructor with require/__dirname/__filename/module/exports provided. The executed payload is fully attacker-controlled from a third-party JSON hosting service. The package also monkey-patches Module.prototype.require to intercept child_process spawn/execSync calls on Windows. Any code hosted at that endpoint runs on the importing machine.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 03:44 AM
- analyzed
- Sep 16, 2026, 03:45 AM
Related advisories
- tol8t@14.0.0
- tetotest@14.0.0
- chai-as-crack@7.0.5
- csa-mfa@1.1.15
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
- discord-resolvers@3.4.2
- n8n-nodes-healthmon@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.