js-crypto-promise@1.0.1
Malicious code in js-crypto-promise (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
js-crypto-promise is a combosquat of the legitimate crypto-promise package. Its postinstall hook (prepinstall.js) base64-decodes a URL to hxxps://jsonkeeper[.]com/b/DWNFF, fetches its content via axios, then spawns a detached node process and pipes the fetched data into stdin — a staged-payload delivery pattern. DNS queries to jsonkeeper[.]com and an axios GET to the endpoint were observed; the install only crashed because the endpoint returned no data. index.js also imports prepinstall.js to trigger the same behaviour on require.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:12 PM
- analyzed
- Jun 10, 2026, 08:13 PM
Related advisories
- mongoose-lean-hooks@0.5.2
- fastify-addon@5.1.0
- modulyn@1.0.1
- mm-ts-utils-client@99.9.1
- mjs-biginteger@5.0.6
- websocket-slot@0.0.6
- metrica-node@2.4.5
- metrica-chain@2.4.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.