LWA-2026-12160 MAL-2026-16215 ↗ confirmed malware

engin1@1.3.99

Malicious code in engin1 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

engin1@1.3.99 executes remote code on import. The package's index.js auto-imports init.js, which spawns a detached `node loader.js` child process. loader.js makes an HTTPS request to hxxps://api[.]npoint[.]io/24c25d5f5fcbb0992a4f, reads the `code` field from the JSON response, base64-decodes it, and executes it via the Function constructor with require/__dirname/__filename/module/exports provided. The executed payload is fully attacker-controlled from a third-party JSON hosting service. The package also monkey-patches Module.prototype.require to intercept child_process spawn/execSync calls on Windows. Any code hosted at that endpoint runs on the importing machine.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 03:44 AM
analyzed
Sep 16, 2026, 03:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.