LWA-2026-6438 MAL-2026-10108 ↗ confirmed malware

url-func-registry@1.0.4

Malicious code in url-func-registry (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package url-func-registry@1.0.4 contains a remote code execution backdoor. The createJsonService() function fetches attacker-controlled code from hxxps://www[.]jsonkeeper[.]com/b/XVHGD and executes it via the Function constructor with Node.js require() access, giving the remote payload full arbitrary code execution capabilities. The code is triggered when consumer code calls getFunc('JsonS'). The package also performs host reconnaissance by fetching from hxxp://ip-api[.]com/json. The package's description as a URL/function registry is a cover for this backdoor.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 06:53 PM
analyzed
Jul 7, 2026, 06:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.