var-helper-kit@1.0.1
Malicious code in var-helper-kit (npm)
Analysis
var-helper-kit@1.0.1 is a host-fingerprinting info-stealer. When loaded (require()), it collects system metadata including process environment, platform, and architecture, then transmits the data via HTTP to an encoded remote server. The code is protected by multi-layer custom base91 obfuscation and anti-debug measures (repeated debugger; calls, source-hash integrity checks). It uses the axios HTTP library to exfiltrate collected host information to the attacker-controlled endpoint. The package has no lifecycle hooks so it does not auto-execute on install — it must be required() by dependent code. The C2 endpoint is encoded and could not be fully resolved by static analysis.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 03:28 PM
- analyzed
- Jun 15, 2026, 03:30 PM
Related advisories
- sam-package@1.0.1
- @resolvx/core@2.4.2
- flow-lending-sdk@9.9.9
- bodega-sdk@9.9.9
- surf-lending@9.9.9
- flowdefi@9.9.9
- flowcardano@9.9.9
- flow-lending@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.