LWA-2026-6590 MAL-2026-10158 ↗ confirmed malware

notify-utilities@1.3.5

Malicious code in notify-utilities (npm)

T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information

Analysis

notify-utilities@1.3.5 is a trojanized clone of the pino logger. On require(), index.js spawns lib/vcall.js as a detached background process. vcall.js fetches a payload from hxxps://api[.]jsonsilo[.]com/public/df71fd55-4f0c-4326-9b5b-a285e38023a5 and executes it via the Function constructor, giving the remote payload full access to Node.js require(). The package name combosquats the real pino/notify ecosystem.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 02:10 PM
analyzed
Jul 10, 2026, 10:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.