async-chain-dom@1.3.5
Malicious code in async-chain-dom (npm)
Analysis
Trojanized clone of the pino logger. When the package is required, index.js spawns a detached child process running lib/vcall.js, which fetches a remote payload from hxxps://api[.]jsonsilo[.]com/public/df71fd55-4f0c-4326-9b5b-a285e38023a5 and executes it via the Function constructor with the full require() scope passed in, giving the remote code full access to the filesystem and Node.js APIs. A secondary C2 domain (vercel-five-coral[.]vercel[.]app) is stored in a shipped .env file. The package has no lifecycle hooks — the payload runs on require(), not install.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 02:10 PM
- analyzed
- Jul 10, 2026, 02:12 PM
Related advisories
- theta-sdk-js@1.2.14
- chunk-parser@1.0.0
- nonenull1@1.0.0
- type-slint@3.3.7
- chai-as-smart@2.3.5
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @wagni_bot/orca-sdk@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.