crypto-promiser@1.0.1
Malicious code in crypto-promiser (npm)
Analysis
crypto-promiser@1.0.1 is a typosquat of the legitimate crypto-promise package. On install, the postinstall hook (prepinstall.js) fetches a payload from hxxps://jsonkeeper[.]com/b/WDT1H via HTTP GET, then pipes the response body into a detached background node process via stdin. This gives the remote payload full code execution on the installer's machine. The child process is spawned with detached:true and unref()'d to persist beyond the install lifecycle.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 07:38 AM
- analyzed
- Jul 7, 2026, 07:39 AM
Related advisories
- express-guardian@1.4.1
- chai-secure@1.2.3
- nodepack-daemon@1.2.9
- pinokio-redis@1.0.127
- chai-as-disarmed@3.2.3
- agn-terminal@0.1.0
- zod-pino434@1.0.127
- internallib_v234@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.