LWA-2026-6372 MAL-2026-7010 ↗ confirmed malware

crypto-promiser@1.0.1

Malicious code in crypto-promiser (npm)

Analysis

crypto-promiser@1.0.1 is a typosquat of the legitimate crypto-promise package. On install, the postinstall hook (prepinstall.js) fetches a payload from hxxps://jsonkeeper[.]com/b/WDT1H via HTTP GET, then pipes the response body into a detached background node process via stdin. This gives the remote payload full code execution on the installer's machine. The child process is spawned with detached:true and unref()'d to persist beyond the install lifecycle.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 07:38 AM
analyzed
Jul 7, 2026, 07:39 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.