LWA-2026-6178 MAL-2026-10114 ↗ confirmed malware

driftpin@1.0.0

Malicious code in driftpin (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195 · Supply Chain Compromise

Analysis

driftpin@1.0.0, described as an SVG sanitizer, is a remote-code-execution dropper. Its index.js exports a getPlugin() function that makes an HTTPS GET request to jsonkeeper[.]com/b/3P9BF, parses the JSON response, and passes the 'model' field directly to eval() — enabling the remote endpoint to execute arbitrary JavaScript on the installer's machine.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 01:48 PM
analyzed
Jun 30, 2026, 01:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.