LWA-2026-6182 MAL-2026-6726 ↗ confirmed malware

db-convertor@1.0.5

Malicious code in db-convertor (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1036 · Masquerading

Analysis

Package masquerades as a MySQL database connector but contains a hidden queryDBConnect() method that decodes a base64-embedded URL (hxxps://jsonkeeper[.]com/b/SH5ZW), fetches a remote payload over HTTPS, spawns a detached Node.js process with stdin piped, and writes the fetched payload into the child process's stdin for remote code evaluation. The child process is spawned with detached:true and unref() to outlive the parent. The payload delivery URL is jsonkeeper[.]com/b/SH5ZW.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 07:23 PM
analyzed
Jun 30, 2026, 07:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.