kisama-js@0.1.8
Malicious code in kisama-js (npm)
Analysis
kisama-js@0.1.8 is a Node.js Remote Access Trojan (RAT) that opens an encrypted command-and-control HTTP+WebSocket server on port 8000. When run, it profiles the host (CPU, memory, disk, OS, kernel version, public IPv4/IPv6 via api[.]ipify[.]org, icanhazip[.]com, checkip[.]amazonaws[.]com, ifconfig[.]me/ip, ipecho[.]net/plain, ipinfo[.]io/ip, myexternalip[.]com/raw, api6[.]ipify[.]org, v6[.]ident[.]me; detects Docker/LXC/Kubernetes/QEMU via cgroup and /proc reads), then exposes remote shell execution (POST /api/exec), full file system access (read/write/upload/download/delete under FILE_ROOT via /api/file/* endpoints), interactive PTY terminal via WebSocket (/api/ws/*), and cron-based task scheduling. C2 traffic is encrypted with ECDSA-signed authentication, ECIES asymmetric encryption, AES-256-GCM session keys, and the Noise Protocol (X25519 key exchange). Default listen address 0[.]0[.]0[.]0:8000; operator configuration via ECDSA_PUBKEY and ECIES_PUBKEY environment variables.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 03:30 AM
- analyzed
- Jun 20, 2026, 03:31 AM
Related advisories
- chunk-parser@1.0.0
- streak-metrics-math@1.0.1
- shiftmarkets-sdk@2.1.0
- react-campaign-optimizer@1.0.0
- node-vfs-polyfill@2.0.5
- stellarfixer@1.0.0
- simple-date-formatter-util-12@1.0.0
- twork-data-services-customer-api-v2-customer-vip-status@20.9.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.