sensivity@2.5.7
Malicious code in sensivity (npm)
Analysis
sensivity@2.5.7 is a trojan disguised as a "Mobile Control Panel". launcher.js masquerades its process as "Runtime Broker", installs HKCU\Run persistence via PowerShell under the fake name "OneDriveUpdate", deploys OneDrive.Standalone.Updater.vbs (named to mimic Microsoft) to silently launch the payload, and monitors Chrome for YouTube tabs to display a QR code (a YouTube session-hijack / cookie-theft pattern). The core logic is a 76KB self-defending obfuscated server.obf.js (~4900 _0x identifiers) loaded via eval(fs.readFileSync(...)). Persistence, masquerading, anti-analysis obfuscation and YouTube-targeted QR phishing are definitive malware indicators.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 02:57 PM
- analyzed
- Jun 1, 2026, 03:06 PM
Related advisories
- sensivity@2.5.39 same package
- sensivity@2.5.38 same package
- sensivity@2.5.25 same package
- sensivity@2.5.24 same package
- sensivity@2.5.5 same package
- sensivity@2.5.3 same package
- sensivity@2.5.2 same package
- sensivity@2.5.0 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.