cputil-node@0.6.6
Malicious code in cputil-node (npm)
Analysis
cputil-node@0.6.6 ships the legitimate cputil wrapper with an injected obfuscated payload appended to its entry point. The published tarball's lib/index.js contains the genuine compiled wrapper (require("./cputil"); exports.default = cputil) followed on the same line by an added self-decoding loader: it sets global['_V']='8-npm3' and global['r']=require, defines a custom string-decoder function that permutes a character array using a constant-seeded index scheme, decodes a 30-character key, and then uses that key to decode two large encoded string blobs (roughly 1.2 KB and 2.4 KB) which are reassembled and executed through a dynamically constructed function. The decoded payload carries both HTTP-client and process-execution capability, so requiring the package can run commands and contact a remote endpoint. The loader is not produced by the package's own build (plain tsc + copyfiles) and is not javascript-obfuscator output — it is a bespoke permutation cipher, which is why generic obfuscation heuristics miss it. The rest of the tarball (the bundled .NET cputil runtime under lib/cputil/bin/linux and lib/cputil/bin/macos, including lib/cputil/bin/linux/cputil) is the legitimate Star cputil binary and is not the malicious component. No plaintext network indicator is recoverable from the injected block: the payload's C2 host, IP and URL path are encrypted inside the encoded blobs and are not present as readable strings in the package.
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 09:04 PM
- analyzed
- Oct 8, 2026, 11:08 AM
Related advisories
- hardhat-bits@2.21.0
- random-certs@0.0.1
- dotenv-runtime@1.0.0
- @subql/common@5.8.3
- hardhat-spack@3.0.2
- testmgkregme@1.0.1
- punypump@1.2.4
- discord-mfa@3.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.