notify-theme@1.3.5
Malicious code in notify-theme (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
notify-theme@1.3.5 is a trojanized clone of the pino logger. When the package is required, index.js spawns a detached child process running lib/caller.js. That file fetches a payload from hxxps://jsonkeeper[.]com/b/EXSIF via axios and executes the response as arbitrary JavaScript code using the Function constructor, enabling remote code execution on the installer's machine. The C2 URL is hardcoded at jsonkeeper[.]com/b/EXSIF.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 07:03 PM
- analyzed
- Jul 1, 2026, 08:19 PM
Related advisories
- chain-chai-async@1.3.5
- notifier-log@1.3.5
- eslint-plus@6.0.4
- react-jsonwebtoken@9.0.3
- chai-as-staged@6.0.4
- buffer-util-internal@1.0.13
- cursed-modules@999.0.0
- db-convertor@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.