LWA-2026-6595 MAL-2026-10418 ↗ confirmed malware

note-utilities@2.1.2

Malicious code in note-utilities (npm)

Analysis

The package is a trojanized logger utility. When required, index.js spawns a detached background process running lib/vcall.js. That script fetches a remote payload from api[.]jsonsilo[.]com/public/94b14d9d-6286-4b13-a7fe-8442e55a31b4 and executes it via the Function constructor, giving the remote server full code execution in the context of the installer's Node.js process. The package has no legitimate functionality — it is a remote-code-execution dropper disguised as a utility library.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 03:39 PM
analyzed
Jul 10, 2026, 07:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.