zenith-utils@12.0.14
Malicious code in zenith-utils (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1546 · Event Triggered ExecutionT1027 · Obfuscated Files or InformationT1105 · Ingress Tool TransferT1573.001 · Symmetric Cryptography
Analysis
The postinstall hook executes a detached Node.js child process that fetches a remote payload from jsonkeeper[.]com (endpoint /b/WDH3V) and evaluates it using the Function constructor with full module access via require. This enables arbitrary remote code execution. The package also ships a 262KB obfuscated/encrypted data blob disguised as a LICENSE file. The package is a trojanized clone: its description, author, and main entry point impersonate unrelated open-source projects (React Training and Nodemailer) while the actual behaviour is a remote code loader.
- analyzed by
- Leitwacht
- first seen
- Jun 24, 2026, 02:55 PM
- analyzed
- Jun 24, 2026, 02:56 PM
Related advisories
- ts-ankle@1.1.0
- node-fetch-utils@1.2.1
- sync-external@1.6.0
- anthropic-claude-latest@4.7.1
- kisama-js@0.1.8
- @resolvx/core@2.4.2
- st-pathhelper@1.0.0
- protectstraizolib@1.0.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.