node-env-resolve@1.0.0
Malicious code in node-env-resolve (npm)
Analysis
node-env-resolve@1.0.0 is a full-featured remote-access trojan published under a benign "environment resolver" description. The postinstall.js copies the package source to a hidden directory (~/.node-gyp-cache or AppData\Roaming\node-gyp-cache), installs dependencies, registers OS-level persistence (Windows HKCU\Run + VBS launcher, macOS LaunchAgent, Linux ~/.config/autostart), and spawns src/index.js as a detached hidden process. The agent connects over a socket[.]io WebSocket to a configurable C2 (default localhost:8471, overridable via SERVER_URL) and supports remote screen capture, microphone audio capture, filesystem browsing and file reads (including .env), browser-history theft from Chrome/Edge/Firefox SQLite stores, remote mouse/keyboard injection (robotjs), and host fingerprinting. Its dependency set (robotjs, screenshot-desktop, socket[.]io-client, node-machine-id, sharp, better-sqlite3) is consistent with a surveillance agent.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:45 AM
- analyzed
- Jun 11, 2026, 11:46 AM
Related advisories
- hex-type@3.0.2
- wormgpt-cli@1.0.1
- node-gyp-runtime@1.0.0
- system-performance-helper@1.0.1
- chunk-parser@1.0.0
- pino-zod@1.0.121
- gpt-terminal-cli@1.0.0
- stellarfixer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.