chalk-ultra@12.0.3
Malicious code in chalk-ultra (npm)
Analysis
chalk-ultra@12.0.3 is a combosquat of the popular chalk package that executes a remote code downloader on install. The postinstall script spawns a detached background Node.js process which fetches a payload from hxxps://jsonkeeper[.]com/b/AD9A2 via HTTP GET and evaluates the response's .cookie field as JavaScript using the Function constructor with full require access — enabling arbitrary code execution controlled by the remote endpoint. The package also ships a 262KB hex-encoded binary blob as a LICENSE file, consistent with encoded payload storage. The C2 URL (jsonkeeper[.]com/b/AD9A2) serves the dynamic stage-2 payload.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 06:56 AM
- analyzed
- Jun 22, 2026, 06:57 AM
Related advisories
- chalk-ultra@12.0.14 same package
- kisama-js@0.1.8
- node-vfs-polyfill@2.0.5
- stellarfixer@1.0.0
- simple-date-formatter-util-12@1.0.0
- twork-data-services-customer-api-v2-customer-vip-status@20.9.7
- streak-int-lib@1.0.0
- text-line-parser@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.