notify-utilities@1.3.5
Malicious code in notify-utilities (npm)
T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information
Analysis
notify-utilities@1.3.5 is a trojanized clone of the pino logger. On require(), index.js spawns lib/vcall.js as a detached background process. vcall.js fetches a payload from hxxps://api[.]jsonsilo[.]com/public/df71fd55-4f0c-4326-9b5b-a285e38023a5 and executes it via the Function constructor, giving the remote payload full access to Node.js require(). The package name combosquats the real pino/notify ecosystem.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 02:10 PM
- analyzed
- Jul 10, 2026, 10:33 PM
Related advisories
- chain-await-dom@1.3.4
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- path-addon-extend@1.0.7
- chai-as-structured@7.0.5
- fastify-addone@5.1.0
- cookie-phase@2.3.5
- chunk-parser@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.