events-runtime@3.2.1
Malicious code in events-runtime (npm)
Analysis
events-runtime@3.2.1 is a combosquat of the real 'events' package and a full command-and-control implant. Its events.js is a copy of Node's EventEmitter with a backdoor in emit(): when args[0].eventId == 'eventId0' it spawns tests/galas-emit.min.js as a detached background process. That payload connects to Slack (api[.]slack[.]com) and Telegram (api[.]telegram[.]org) using bundled hardcoded bot tokens, fingerprints the victim (hostname, platform, arch, CPUs, memory, uptime) and beacons to both channels; it also reaches Sepolia testnet RPC via Infura/Alchemy and interacts with smart contracts for C2 orchestration. A second payload, errors.min.js, polls Slack conversations.history for AES-GCM-encrypted commands, downloads files in chunks, writes them to disk and spawns them as detached node processes. Both payloads carry a worm-style self-propagation marker ('REDISTRIBUTION REQUIRES INCLUSION OF THIS LICENSE.').
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 08:43 AM
- analyzed
- Jun 8, 2026, 08:49 AM
- weekly installs
- 87,925
Related advisories
- events-runtime@3.2.2 same package
- events-runtime@3.2.3 same package
- botmaker-cli@0.1.19
- cloudndmcedu@1.0.0
- ndmckauxuoincv@1.0.0
- tailwind-form-styles@0.5.1
- kamafhbnowct@1.0.0
- @biz44/id95-client@1.1.96
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.