velocityfix@1.0.0
Malicious code in velocityfix (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1070.004 · File Deletion
Analysis
Package 'velocityfix' typosquats the Minecraft Velocity proxy. Its postinstall script (scripts/loader.js) downloads a native executable from store6[.]gofile[.]io/download/web/bcd38d7d-1647-4448-a448-037d58ad9413/payload.exe, saves it to the system temp directory, launches it silently in the background with `start /b`, then deletes the executable after 5 seconds. The package also bundles a copy of the same executable (payload.exe, 1.7 MB) as a fallback. The gofile[.]io host is the external payload source.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 11:35 PM
- analyzed
- Jun 25, 2026, 11:35 PM
Related advisories
- node-core-libs@1.0.0
- ordered-btree@3.2.2
- @caspianph/storyteller@1.1.13
- vite-plugin-vue-extend@1.0.9
- vfat-tools@2.0.0
- sickle-wrapper@0.2.0
- mailconfirmer@3.3.12
- redeem-onchain-sdk@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.