laycot@1.3.10
Malicious code in laycot (npm)
Analysis
laycot@1.3.10 is a remote-code-execution dropper. Importing the package automatically spawns a detached background `node loader.js` process (PID persisted to a .pid file). loader.js fetches a remote configuration from hxxps://api[.]npoint[.]io/641d37178a880b1e8b8f, base64-decodes the `code` field from the JSON response, and executes it via the Function constructor with require/__dirname/__filename/module/exports injected. The executed payload is served remotely and is not present in the package, so its behaviour is fully controlled by the remote endpoint. The loader also monkey-patches child_process.spawn/execSync to force windowsHide on Windows. The package makes outbound network contact on execution.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 12:20 AM
- analyzed
- Sep 17, 2026, 12:20 AM
Related advisories
- process-lhpm@1.1.79
- @railone/image-utils@1.1.10
- @biz44/runtime-utils@1.1.11
- id79-client@1.1.79
- @biz44/id95-client@1.1.96
- @biz44/id12-client@1.1.13
- hydration-cls-ui@1.0.0
- dim-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.