LWA-2026-5952 MAL-2026-6401 ↗ confirmed malware

zenith-utils@12.0.14

Malicious code in zenith-utils (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1546 · Event Triggered ExecutionT1027 · Obfuscated Files or InformationT1105 · Ingress Tool TransferT1573.001 · Symmetric Cryptography

Analysis

The postinstall hook executes a detached Node.js child process that fetches a remote payload from jsonkeeper[.]com (endpoint /b/WDH3V) and evaluates it using the Function constructor with full module access via require. This enables arbitrary remote code execution. The package also ships a 262KB obfuscated/encrypted data blob disguised as a LICENSE file. The package is a trojanized clone: its description, author, and main entry point impersonate unrelated open-source projects (React Training and Nodemailer) while the actual behaviour is a remote code loader.

analyzed by
Leitwacht
first seen
Jun 24, 2026, 02:55 PM
analyzed
Jun 24, 2026, 02:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.