unicode-colors@4.1.4
Malicious code in unicode-colors (npm)
Analysis
Package unicode-colors@4.1.4 carries a malicious preinstall script (dist/util.js) that runs on 'npm install'. The script evades detection by checking for virtualized environments (VMware, VirtualBox, KVM, Hyper-V MAC address prefixes), available CPU cores, free memory, system uptime (<2 hours), and sandbox hostnames. If no sandbox is detected, it makes an HTTPS request to an obfuscated C2 server and executes the response body via eval() — a second-stage remote code execution payload. The package is named misleadingly "unicode-colors" but ships the unrelated LayUI front-end framework as cover. It executes arbitrary code from its C2 on every install.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:59 AM
- analyzed
- Jun 15, 2026, 11:00 AM
Related advisories
- hex-type@3.0.2
- farming-tools-12@4.68.54
- os-ulid-void@3.0.2
- wallet-sdk-9@3.7.73
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.