@marketfront/bannerpopup@7.0.0
Malicious code in @marketfront/bannerpopup (npm)
Analysis
The postinstall script (scripts/postinstall.js) is a 164KB heavily obfuscated JavaScript payload using javascript-obfuscator with array shuffling, RC4/XOR string decryption, and anti-debugging checks that scan process.argv for profiler/debugger flags and process.env.NODE_OPTIONS. The package claims to be an internal authentication client but ships no actual library code (dist/index.js is a 76-byte stub pointing to a non-existent file), has zero dependencies, and the repository URL points to a non-existent domain. The obfuscated postinstall runs automatically on npm install.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 11:09 PM
- analyzed
- Jul 1, 2026, 11:11 PM
Related advisories
- @marketfront/fingerprint@7.0.0
- @marketfront/changefilter@7.0.0
- @marketfront/actualordersnippetpopup@7.0.0
- @digitalcnzz/embedded-sdk@1.0.7
- util-free-ports@3.1.2
- stringfy-utils-kit@1.0.0
- sort-btree@2.1.4
- macos-ci-utils@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.