vemos-sdk@1.0.0
Malicious code in vemos-sdk (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
vemos-sdk@1.0.0 is a second-stage dropper. Its postinstall hook (node index.js) calls getVemosInterface(), which base64-decodes the string aHR0cHM6Ly9qc29ua2VlcGVyLmNvbS9iL0JONzdL to hxxps://jsonkeeper[.]com/b/BN77K, fetches that URL via axios GET, and writes the response's 'cookie' field into the stdin of a detached 'node' subprocess spawned with detached:true and unref() for stealth and persistence. The throwaway publisher email and the remote-fetch-then-execute pattern make this a payload dropper.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 02:37 AM
- analyzed
- Jun 10, 2026, 02:38 AM
Related advisories
- chai-check-error@2.1.3
- db-xorma@1.0.2
- os-ulid-void@3.0.2
- path-internal@1.0.15
- jsontoken-extend@1.0.13
- events-runtime@3.2.1
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.