@keeneye/toolkit@5.0.1
Malicious code in @keeneye/toolkit (npm)
Analysis
@keeneye/toolkit@5.0.1 is an install-time RCE dropper. The postinstall.js (13.5KB, 562 obfuscated identifiers) downloads platform-specific payloads via HTTP/HTTPS and spawns them as child processes. The package's dist/index.js requires a non-existent src/index.js — zero runtime functionality, purely a delivery vehicle. Version history is fabricated (first publish claims 5.0.1). The README admits 'telemetry' to telemetry[.]keeneye[.]io as a cover story, but the code downloads and executes arbitrary binaries, not telemetry posts. No direct token-theft markers found. Tarball scan missed this because the lifecycle hook is 'node scripts/postinstall.js' (JS-level, not shell), bypassing shell-level detectors. This is a classic remote code execution supply-chain attack pattern.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 03:44 PM
- analyzed
- Jun 1, 2026, 03:49 PM
Related advisories
- @keeneye/uikit@5.0.1
- @gbrlxvi/ts-form-utils@2.1.1
- sensivity@2.5.7
- sensivity@2.5.5
- sensivity@2.5.3
- sensivity@2.5.2
- sensivity@2.5.0
- argoncrypt@1.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.