buffer-util-internal@1.0.13
Malicious code in buffer-util-internal (npm)
Analysis
buffer-util-internal@1.0.13 is a trojanized clone of the legitimate feross/buffer module. It contains a copy of the original buffer implementation but injects an IIFE at module top-level that: 1) base64-decodes the URL hxxps://www[.]jsonkeeper[.]com/b/PT0ON, 2) fetches JSON from that endpoint, and 3) evals the "content" field — executing arbitrary remote code at require() time. A second commented-out endpoint (hxxps://www[.]jsonkeeper[.]com/b/CWOV9) indicates prior testing. The package has no repository of its own, zero-byte README/LICENSE files, and includes unnecessary dependencies (execp, fs@0.0.1-security, path@0.12.7) consistent with a supply-chain attack.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 09:48 PM
- analyzed
- Jun 30, 2026, 09:48 PM
Related advisories
- cursed-modules@999.0.0
- db-convertor@1.0.5
- auth-next-gen@1.6.29
- driftpin@1.0.0
- nullrift@1.0.0
- multer-orm@2.0.2
- notify-logs@1.3.5
- assertcoreutils@2.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.