swnwall@1.2.10
Malicious code in swnwall (npm)
Analysis
swnwall@1.2.10 executes remote code on import. Importing the module (index.js) auto-spawns a detached background `node loader.js` process (persistence via a .pid file). loader.js fetches a JSON payload from hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes the `code` field, and executes it via the Function constructor with full require/module context — a fully attacker-controlled second stage with no payload shipped in the package. The package also monkeypatches child_process.spawn/execSync to force windowsHide. The declared purpose ("Special layout set module") does not match this behaviour.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 05:35 AM
- analyzed
- Sep 16, 2026, 05:35 AM
Related advisories
- engin1@1.3.99
- tol8t@14.0.0
- tetotest@14.0.0
- chai-as-crack@7.0.5
- csa-mfa@1.1.15
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
- discord-resolvers@3.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.