process-mite@1.1.79
Malicious code in process-mite (npm)
Analysis
process-mite@1.1.79 executes remote code on import. Importing the package auto-runs an initializer that spawns a detached background `node loader.js` process (persisting its PID to a .pid file). loader.js fetches a JSON document from hxxps://api[.]npoint[.]io/33e8d008c334b060adad, base64-decodes the `code` field, and executes it via the Function constructor with require/__dirname/__filename/module/exports supplied — a remote-code-execution dropper whose payload is served remotely rather than shipped in the package. The package also monkey-patches Module.prototype.require to intercept child_process calls. The remote payload is not present in the tarball, so its full behaviour is determined by the fetched code.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 09:20 AM
- analyzed
- Sep 16, 2026, 09:21 AM
Related advisories
- element-plus-vite-cli@2.9.3
- @asenfotech/unplugin-element-plus@2.9.3
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-pysh-meeb@3.6.8
- strapi-plugin-ccip-meeb@3.6.8
- strapi-plugin-conresh-meeb@3.6.8
- strapi-plugin-cccon-meeb@3.6.8
- swnwall@1.2.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.