url-func-registry@1.0.4
Malicious code in url-func-registry (npm)
Analysis
Package url-func-registry@1.0.4 contains a remote code execution backdoor. The createJsonService() function fetches attacker-controlled code from hxxps://www[.]jsonkeeper[.]com/b/XVHGD and executes it via the Function constructor with Node.js require() access, giving the remote payload full arbitrary code execution capabilities. The code is triggered when consumer code calls getFunc('JsonS'). The package also performs host reconnaissance by fetching from hxxp://ip-api[.]com/json. The package's description as a URL/function registry is a cover for this backdoor.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 06:53 PM
- analyzed
- Jul 7, 2026, 06:55 PM
Related advisories
- @vite-ln/build-ts@5.17.0
- chain-async-dom@1.3.6
- @vite-tab/tab@5.7.0
- tipsen-last@1.0.0
- react-next-vite@1.2.9
- mongoose-schema-unique@4.0.4
- motion-pull@2.3.5
- configration@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.