LWA-2026-3791 MAL-2026-5855 ↗ confirmed malware

vemos-sdk@1.0.0

Malicious code in vemos-sdk (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

vemos-sdk@1.0.0 is a second-stage dropper. Its postinstall hook (node index.js) calls getVemosInterface(), which base64-decodes the string aHR0cHM6Ly9qc29ua2VlcGVyLmNvbS9iL0JONzdL to hxxps://jsonkeeper[.]com/b/BN77K, fetches that URL via axios GET, and writes the response's 'cookie' field into the stdin of a detached 'node' subprocess spawned with detached:true and unref() for stealth and persistence. The throwaway publisher email and the remote-fetch-then-execute pattern make this a payload dropper.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 02:37 AM
analyzed
Jun 10, 2026, 02:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.