LWA-2026-6591 MAL-2026-10406 ↗ confirmed malware

async-chain-dom@1.3.5

Malicious code in async-chain-dom (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

Trojanized clone of the pino logger. When the package is required, index.js spawns a detached child process running lib/vcall.js, which fetches a remote payload from hxxps://api[.]jsonsilo[.]com/public/df71fd55-4f0c-4326-9b5b-a285e38023a5 and executes it via the Function constructor with the full require() scope passed in, giving the remote code full access to the filesystem and Node.js APIs. A secondary C2 domain (vercel-five-coral[.]vercel[.]app) is stored in a shipped .env file. The package has no lifecycle hooks — the payload runs on require(), not install.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 02:10 PM
analyzed
Jul 10, 2026, 02:12 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.