node-env-resolve@1.2.3
Malicious code in node-env-resolve (npm)
Analysis
node-env-resolve@1.2.3 is a remote-access trojan disguised as an environment-configuration helper. Its postinstall hook (postinstall.js) copies the bundled src/ tree into a hidden per-user directory — ~/.node-gyp-cache on macOS/Linux, %APPDATA%\node-gyp-cache on Windows — installs persistence, and launches a detached background agent. Persistence is registered on every platform: a HKCU\Run registry value plus a Startup-folder launcher.vbs on Windows, a LaunchAgent plist loaded with launchctl on macOS, and a ~/.config/autostart/connector.desktop entry on Linux. The agent registers with the operator relay at hxxps://connector-server-xi[.]vercel[.]app (endpoints /api/agent/register, /api/agent/heartbeat, /api/agent/signal, /api/agent/signal/poll), reporting machineId, hostname and public IP, then polls for commands. Bundled modules give the operator file listing/read/write (src/fileScanner.js), browser-history extraction from Chrome/Edge/Firefox SQLite databases (src/browserHistory.js), screen capture (src/screenCapture.js), microphone and system-audio capture via ffmpeg (src/audioCapture.js), remote input control (src/inputHandler.js) and a WebRTC P2P channel (src/p2pManager.js, node-datachannel); captured data is relayed to the server and over the P2P channel. The declared purpose ("Lightweight environment configuration resolver for Node.js") does not match any of this behaviour.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 09:53 AM
- analyzed
- Oct 8, 2026, 12:02 PM
Related advisories
- node-env-resolve@1.0.0 same package
- wormgpt-cli@1.0.1
- system-performance-helper@1.0.1
- node-gyp-runtime@1.0.0
- ulid-intel@2.12.3
- streak-metrics-core@1.0.0
- json-validator-utils@1.0.1
- solana-key-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.