vitest-agent@1.0.5
Malicious code in vitest-agent (npm)
Analysis
vitest-agent@1.0.5 is a combosquat of the vitest test runner, shipping a trojanized copy of the nodemailer library. The postinstall hook (node lib/utils/index.js) spawns a detached child process running lib/utils/smtp-connection/index.js, which fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/UTUUE and executes it via new Function("require", ...). The payload URL is resolved at install time and the fetched code runs with full access to the installer's Node.js environment.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 03:29 PM
- analyzed
- Jul 1, 2026, 08:19 PM
- weekly installs
- 170
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.