zredis-typed@1.0.127
Malicious code in zredis-typed (npm)
Analysis
zredis-typed@1.0.127 is a combosquat package (unrelated to Redis) that installs a full remote-access trojan (RAT) on the victim's machine. On `npm install`, the postinstall chain runs five scripts that: (1) patch a clipboard-event native binary; (2) build the dist/ directory; (3) copy the agent to a hidden durable runtime under `~/.local/share/cfgmgr/.forge-jsxy/runtime/` (or `%LOCALAPPDATA%\CfgMgr\data\.forge-jsxy\runtime\` on Windows); (4) register OS autostart via `forge-autostart` (Windows registry/Linux systemd/macOS LaunchAgent); (5) spawn a detached background process (`forge-agent`). The agent performs: clipboard monitoring and exfiltration, keyboard input capture, full-desktop screenshot capture (uploaded via Discord webhooks), remote file-system access (file explorer served over WebSocket), Chromium browser extension database harvesting, filesystem-wide secret/credential scanning, and Discord bot token abuse. The C2 channel is an encrypted WebSocket relay — the relay host and port are AES-256-GCM encrypted in `dist/deploymentDefaults.js` with an XOR-obfuscated embedded decryption key. The relay server also serves a self-update tarball at `/api/zredis-typed-package.tgz`. The agent connects to the relay on startup and accepts remote commands including file read/write, screenshot capture, terminal execution, and extension-database exfiltration.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 06:04 PM
- analyzed
- Jul 5, 2026, 06:05 PM
Related advisories
- yian666aikf@1.0.3
- texttweak-kit@1.0.0
- npm-scanner@1.0.0
- nodecheck-health@1.0.0
- gpt-terminal-cli@1.0.0
- ezdiscordbots@1.0.2
- streak-map-kit@1.0.0
- streak-kit-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.