events-runtime@3.2.1
Malicious code in events-runtime (npm)
Analysis
events-runtime@3.2.1 is a combosquat of the real 'events' package and a full command-and-control implant. Its events.js is a copy of Node's EventEmitter with a backdoor in emit(): when args[0].eventId == 'eventId0' it spawns tests/galas-emit.min.js as a detached background process. That payload connects to Slack (api[.]slack[.]com) and Telegram (api[.]telegram[.]org) using bundled hardcoded bot tokens, fingerprints the victim (hostname, platform, arch, CPUs, memory, uptime) and beacons to both channels; it also reaches Sepolia testnet RPC via Infura/Alchemy and interacts with smart contracts for C2 orchestration. A second payload, errors.min.js, polls Slack conversations.history for AES-GCM-encrypted commands, downloads files in chunks, writes them to disk and spawns them as detached node processes. Both payloads carry a worm-style self-propagation marker ('REDISTRIBUTION REQUIRES INCLUSION OF THIS LICENSE.').
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 08:43 AM
- analyzed
- Jun 8, 2026, 08:49 AM
- weekly installs
- 87,925
Related advisories
- events-runtime@3.2.2 same package
- events-runtime@3.2.3 same package
- @kolbo/mcp@1.57.1
- map-streak-kit@1.0.0
- platform-ui-colors@35.8.1
- dolyame-ui-buttonstore@35.8.1
- streak-kit-map@1.0.0
- streak-map-cache@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.