node-denv@1.3.5
Malicious code in node-denv (npm)
Analysis
node-denv@1.3.5 is a trojanized package that impersonates a pino-like logger but is a remote code loader. The publisher (sixabi6107@mtupu. index.js exports middleware that spawns lib/caller.js as a detached subprocess (child.unref()), bypassing the parent lifecycle. caller.js fetches attacker-controlled code from hxxps://jsonkeeper[.]com/b/EXSIF via axios and executes it with new Function.constructor("require", s) after retrying up to 5 times, giving the attacker arbitrary code execution on the installer's machine. Console.log is stashed/restored to hide traces. The package name (node-denv) and metadata (pino keywords, "Robert King" author) are deceptive — the publisher email is a disposable domain.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:44 AM
- analyzed
- Jun 11, 2026, 11:47 AM
Related advisories
- vite-config-optimizer@1.1.4
- dolyame-boxy-atom-bnpl-navigation-arrow@35.6.5
- devplatform-spa-plugin-s3-module-loader@35.8.2
- bigops-create-manifest@35.2.4
- bigops-cobrowsing@35.4.9
- terminal-kit-tslint-config@20.1.9
- twork-data-services-aggregator-sme-task-info@20.3.1
- statist-browser-typed-client-risktech.uwfrontantifraud.events@20.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.