crypto-promiser@1.0.1
Malicious code in crypto-promiser (npm)
Analysis
crypto-promiser@1.0.1 is a typosquat of the legitimate crypto-promise package. On install, the postinstall hook (prepinstall.js) fetches a payload from hxxps://jsonkeeper[.]com/b/WDT1H via HTTP GET, then pipes the response body into a detached background node process via stdin. This gives the remote payload full code execution on the installer's machine. The child process is spawned with detached:true and unref()'d to persist beyond the install lifecycle.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 07:38 AM
- analyzed
- Jul 7, 2026, 07:39 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.