node-converter@1.0.0
Malicious code in node-converter (npm)
Analysis
node-converter@1.0.0 is a remote dropper. Its converter() function hex-decodes the URL 'hxxps://api[.]etherjs[.]pro/socket' (spoofed ethers.js domain), fetches a base64-decoded second-stage payload from that endpoint, writes it to a temp directory, npm-installs data-harvesting packages (active-win for active-window capture, clipboardy for clipboard theft, node-key for keylogging, archiver for archiving stolen data, ws for WebSocket exfil), then spawns the second stage as a detached+hidden background process (windowsHide:true, stdio:'ignore', child.unref()). No NPM_TOKEN/GITHUB_TOKEN markers found, but the dropper+data-harvesting dependency chain is a clear supply-chain attack.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:44 AM
- analyzed
- Jun 11, 2026, 11:45 AM
Related advisories
- sn-internal-test@1.9.9
- nodecheck-health@1.0.0
- self-certificate@1.0.0
- nj-logger@1.3.2
- reading-cookies@6.13.2
- niieani@7.9.0
- ng-search-api@99.9.1
- ts-ecro@0.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.