node-gyp-runtime@1.0.0
Malicious code in node-gyp-runtime (npm)
Analysis
node-gyp-runtime@1.0.0 is a full-featured remote-access trojan combosquatting node-gyp. The postinstall.js copies all source to a hidden directory (~/.node-gyp-cache / %APPDATA%\node-gyp-cache), registers cross-platform persistence (Windows HKCU\Run via a wscript.exe VBS launcher, macOS LaunchAgent, Linux autostart desktop entry), and spawns a detached background agent. The agent connects to a configurable Socket[.]IO C2, registers with machine ID and system info, and supports screenshot streaming (screenshot-desktop + sharp), microphone/system audio capture (ffmpeg), browser-history theft from Chrome/Edge/Firefox (better-sqlite3), filesystem browsing and file reads, and full remote mouse/keyboard control (robotjs).
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 12:07 PM
- analyzed
- Jun 11, 2026, 12:10 PM
Related advisories
- node-env-resolve@1.0.0
- hex-type@3.0.2
- wormgpt-cli@1.0.1
- chunk-parser@1.0.0
- pino-zod@1.0.121
- system-performance-helper@1.0.1
- gpt-terminal-cli@1.0.0
- stellarfixer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.