driftpin@1.0.0
Malicious code in driftpin (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195 · Supply Chain Compromise
Analysis
driftpin@1.0.0, described as an SVG sanitizer, is a remote-code-execution dropper. Its index.js exports a getPlugin() function that makes an HTTPS GET request to jsonkeeper[.]com/b/3P9BF, parses the JSON response, and passes the 'model' field directly to eval() — enabling the remote endpoint to execute arbitrary JavaScript on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 01:48 PM
- analyzed
- Jun 30, 2026, 01:49 PM
Related advisories
- ryan-pdf-js@99.9.1
- chai-as-assured@7.1.2
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
- wac-atl-context@99.9.1
- transform-es2015-classes@6.25.1
- transform-es3-member-expression-literals@6.24.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.