LWA-2026-6177 MAL-2026-10206 ↗ confirmed malware

nullrift@1.0.0

Malicious code in nullrift (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

nullrift@1.0.0 is a trojanized SVG sanitizer utility. The index.js exports a getPlugin() function that, when invoked, sends an HTTPS GET to hxxps://www[.]jsonkeeper[.]com/b/3P9BF with a custom header (bearrtoken: "logo"), parses the JSON response, and executes the value of the 'model' field via eval(). This enables arbitrary remote code execution from a third-party JSON-hosting service, which can serve updated payloads at any time. The package also contains a decoy SVG sanitization module to appear legitimate.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 01:48 PM
analyzed
Jun 30, 2026, 01:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.