LWA-2026-6184 MAL-2026-10151 ↗ confirmed malware

buffer-util-internal@1.0.13

Malicious code in buffer-util-internal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

buffer-util-internal@1.0.13 is a trojanized clone of the legitimate feross/buffer module. It contains a copy of the original buffer implementation but injects an IIFE at module top-level that: 1) base64-decodes the URL hxxps://www[.]jsonkeeper[.]com/b/PT0ON, 2) fetches JSON from that endpoint, and 3) evals the "content" field — executing arbitrary remote code at require() time. A second commented-out endpoint (hxxps://www[.]jsonkeeper[.]com/b/CWOV9) indicates prior testing. The package has no repository of its own, zero-byte README/LICENSE files, and includes unnecessary dependencies (execp, fs@0.0.1-security, path@0.12.7) consistent with a supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 09:48 PM
analyzed
Jun 30, 2026, 09:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.