note-utilities@2.1.2
Malicious code in note-utilities (npm)
Analysis
The package is a trojanized logger utility. When required, index.js spawns a detached background process running lib/vcall.js. That script fetches a remote payload from api[.]jsonsilo[.]com/public/94b14d9d-6286-4b13-a7fe-8442e55a31b4 and executes it via the Function constructor, giving the remote server full code execution in the context of the installer's Node.js process. The package has no legitimate functionality — it is a remote-code-execution dropper disguised as a utility library.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 03:39 PM
- analyzed
- Jul 10, 2026, 07:13 PM
Related advisories
- chain-await-dom@1.3.4
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- path-addon-extend@1.0.7
- chai-as-structured@7.0.5
- fastify-addone@5.1.0
- cookie-phase@2.3.5
- chunk-parser@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.