mailconfirmer@3.3.21
Malicious code in mailconfirmer (npm)
Analysis
The package mailconfirmer@3.3.21 claims to provide email verification utilities but instead runs a postinstall hook (install-hook.js) that spawns a hidden, detached PowerShell process (powershell -NoP -NonI -W Hidden -Enc) executing a base64-encoded payload. The PowerShell window is hidden and the process is detached so it outlives the npm install session and avoids user visibility. The base64-encoded command string is the payload stage; the actual decoded command is not recoverable from the available artifact. The package has no repository and its declared purpose is unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:57 AM
- analyzed
- Jun 27, 2026, 09:19 PM
- weekly installs
- 8,004
Related advisories
- mailconfirmer@3.3.11 same package
- mailconfirmer@3.3.12 same package
- shadxino@1.0.7
- @npmresearch3/metrics-probe-dfda@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
- env-config-f281@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.