db-convertor@1.0.5
Malicious code in db-convertor (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1036 · Masquerading
Analysis
Package masquerades as a MySQL database connector but contains a hidden queryDBConnect() method that decodes a base64-embedded URL (hxxps://jsonkeeper[.]com/b/SH5ZW), fetches a remote payload over HTTPS, spawns a detached Node.js process with stdin piped, and writes the fetched payload into the child process's stdin for remote code evaluation. The child process is spawned with detached:true and unref() to outlive the parent. The payload delivery URL is jsonkeeper[.]com/b/SH5ZW.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 07:23 PM
- analyzed
- Jun 30, 2026, 07:24 PM
Related advisories
- obfus-jsxy@3.2.0
- mev-shield@1.4.2
- metrica-node@2.4.5
- prettier_v2@3.8.5
- ded-aa-common-ded-aa-common-core@35.1.6
- bnpl-blocks-independent-bnpl-open-api@35.1.2
- bigops-api@35.8.8
- dolyame-ui-loader@35.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.