LWA-2026-4231 MAL-2025-47873 ↗ confirmed malware

node-converter@1.0.0

Malicious code in node-converter (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

node-converter@1.0.0 is a remote dropper. Its converter() function hex-decodes the URL 'hxxps://api[.]etherjs[.]pro/socket' (spoofed ethers.js domain), fetches a base64-decoded second-stage payload from that endpoint, writes it to a temp directory, npm-installs data-harvesting packages (active-win for active-window capture, clipboardy for clipboard theft, node-key for keylogging, archiver for archiving stolen data, ws for WebSocket exfil), then spawns the second stage as a detached+hidden background process (windowsHide:true, stdio:'ignore', child.unref()). No NPM_TOKEN/GITHUB_TOKEN markers found, but the dropper+data-harvesting dependency chain is a clear supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:44 AM
analyzed
Jun 11, 2026, 11:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.