notify-utilities@1.3.5
Malicious code in notify-utilities (npm)
T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information
Analysis
notify-utilities@1.3.5 is a trojanized clone of the pino logger. On require(), index.js spawns lib/vcall.js as a detached background process. vcall.js fetches a payload from hxxps://api[.]jsonsilo[.]com/public/df71fd55-4f0c-4326-9b5b-a285e38023a5 and executes it via the Function constructor, giving the remote payload full access to Node.js require(). The package name combosquats the real pino/notify ecosystem.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 02:10 PM
- analyzed
- Jul 10, 2026, 10:33 PM
Related advisories
- client-cookies-agent@99.9.7
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- eth-react-redirection@1.0.0
- ohcm-culture-formatting@5.0.0
- theta-sdk-js@1.2.14
- chunk-parser@1.0.0
- nonenull1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.