random-certs@0.0.1
Malicious code in random-certs (npm)
Analysis
random-certs@0.0.1 presents itself as a random self-signed certificate generator, but index.js hides a remote-code dropper. Its loadSampleCertificate() function reads the bundled file sample/cert.pem, strips the PEM header/footer, base64-decodes the body and passes the result to eval(); generateCertificates() calls this on every invocation, so the hidden code runs as soon as the advertised API is used. The file named sample/cert.pem is not a certificate — it decodes to JavaScript that base64-decodes an embedded URL, fetches it, and pipes the response body into a detached interpreter process: spawn('python3' on POSIX, 'python' on win32, ['-'], {stdio:['pipe','ignore','ignore'], detached:true, windowsHide:true}) followed by stdin.write(body), stdin.end() and unref(), with all errors silently swallowed. The fetched content is only executed if its content-type is not text/html, a guard against Google Drive's HTML interstitial. The staging URL is a Google Drive download link (drive[.]usercontent[.]google[.]com/download?id=1y4LSiUb4PZSgJKBtEVJMDNnl3Sr7kbSy), so the second stage is fetched from a legitimate web service rather than a fixed attacker domain. The encoded_cert and encoded_key constants inside the payload are unused decoys. The package declares no lifecycle scripts, so the payload is triggered by calling generateCertificates() rather than at install time.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 06:46 AM
- analyzed
- Oct 7, 2026, 06:47 AM
Related advisories
- wallet-connect-adapter@1.4.2
- sysdo@1.0.0
- core-js-buffer@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- txs-builder@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.