dotnet-runtime-base@1.0.5
Malicious code in dotnet-runtime-base (npm)
T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File
Analysis
Combosquat package impersonating .NET runtime infrastructure. On Windows systems, the postinstall hook (install.js) writes a PowerShell script to the temp directory that downloads a remote binary from hxxps://raw[.]githubusercontent[.]com/cphc811-ui/d3d/main/npm-sc-legit[.]exe and executes it with hidden window. The package's index.js exports trivial string-utility functions as a decoy. The downloaded binary is a second-stage payload whose behaviour is unknown but the delivery mechanism is a classic dropper.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 07:09 AM
- analyzed
- Jul 12, 2026, 07:09 AM
Related advisories
- mailconfirmer@3.3.11
- mailconfirmer@3.3.21
- shadxino@1.0.7
- @npmresearch3/metrics-probe-dfda@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
- env-config-f281@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.