async-chain-dom@1.3.5
Malicious code in async-chain-dom (npm)
Analysis
Trojanized clone of the pino logger. When the package is required, index.js spawns a detached child process running lib/vcall.js, which fetches a remote payload from hxxps://api[.]jsonsilo[.]com/public/df71fd55-4f0c-4326-9b5b-a285e38023a5 and executes it via the Function constructor with the full require() scope passed in, giving the remote code full access to the filesystem and Node.js APIs. A secondary C2 domain (vercel-five-coral[.]vercel[.]app) is stored in a shipped .env file. The package has no lifecycle hooks — the payload runs on require(), not install.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 02:10 PM
- analyzed
- Jul 10, 2026, 02:12 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.