web-pool@2.3.5
Malicious code in web-pool (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1055 · Process Injection
Analysis
The package index.js spawns a detached child process running lib/initializeCaller.js, which immediately POSTs the full process.env to hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df and then executes the response body as Node.js code via new Function("require", response.data), giving the remote server arbitrary code execution on the installers machine. The C2 host is ipcheck-hashed[.]vercel[.]app.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 02:44 AM
- analyzed
- Jun 16, 2026, 02:46 AM
Related advisories
- sort-btree@2.1.4
- poxios-chain@1.3.5
- npm-scanner@1.0.0
- hex-type@3.0.2
- @solana-js/web3@1.91.3
- bigops-security@35.8.8
- delivery-ci-jira@35.5.2
- bigops-api-customer@35.8.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.