LWA-2026-12171 MAL-2026-16224 ↗ confirmed malware

process-mite@1.1.79

Malicious code in process-mite (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

process-mite@1.1.79 executes remote code on import. Importing the package auto-runs an initializer that spawns a detached background `node loader.js` process (persisting its PID to a .pid file). loader.js fetches a JSON document from hxxps://api[.]npoint[.]io/33e8d008c334b060adad, base64-decodes the `code` field, and executes it via the Function constructor with require/__dirname/__filename/module/exports supplied — a remote-code-execution dropper whose payload is served remotely rather than shipped in the package. The package also monkey-patches Module.prototype.require to intercept child_process calls. The remote payload is not present in the tarball, so its full behaviour is determined by the fetched code.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 09:20 AM
analyzed
Sep 16, 2026, 09:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.