nullrift@1.0.0
Malicious code in nullrift (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
nullrift@1.0.0 is a trojanized SVG sanitizer utility. The index.js exports a getPlugin() function that, when invoked, sends an HTTPS GET to hxxps://www[.]jsonkeeper[.]com/b/3P9BF with a custom header (bearrtoken: "logo"), parses the JSON response, and executes the value of the 'model' field via eval(). This enables arbitrary remote code execution from a third-party JSON-hosting service, which can serve updated payloads at any time. The package also contains a decoy SVG sanitization module to appear legitimate.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 01:48 PM
- analyzed
- Jun 30, 2026, 01:48 PM
Related advisories
- multer-orm@2.0.2
- notify-logs@1.3.5
- assertcoreutils@2.3.2
- chai-as-buffered@3.7.24
- lil-swisgom-hlepers@1.0.0
- chai-promised-test@1.3.5
- hardhat-compile-ethers@0.0.1
- jwtmethod@1.1.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.