LWA-2026-2981 MAL-2026-5528 ↗ confirmed malware

events-runtime@3.2.1

Malicious code in events-runtime (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1102 · Web ServiceT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

events-runtime@3.2.1 is a combosquat of the real 'events' package and a full command-and-control implant. Its events.js is a copy of Node's EventEmitter with a backdoor in emit(): when args[0].eventId == 'eventId0' it spawns tests/galas-emit.min.js as a detached background process. That payload connects to Slack (api[.]slack[.]com) and Telegram (api[.]telegram[.]org) using bundled hardcoded bot tokens, fingerprints the victim (hostname, platform, arch, CPUs, memory, uptime) and beacons to both channels; it also reaches Sepolia testnet RPC via Infura/Alchemy and interacts with smart contracts for C2 orchestration. A second payload, errors.min.js, polls Slack conversations.history for AES-GCM-encrypted commands, downloads files in chunks, writes them to disk and spawns them as detached node processes. Both payloads carry a worm-style self-propagation marker ('REDISTRIBUTION REQUIRES INCLUSION OF THIS LICENSE.').

analyzed by
Leitwacht
first seen
Jun 8, 2026, 08:43 AM
analyzed
Jun 8, 2026, 08:49 AM
weekly installs
87,925

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.