pure-folder-three@0.7.3
Malicious code in pure-folder-three (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter
Analysis
The postinstall hook (src/build.js) constructs an obfuscated HTTPS URL from encoded numeric constants and makes a request to a remote C2 server. The response header 'm' is executed as a shell command via child_process.execSync, giving the attacker arbitrary remote code execution on the installer's machine. The payload skips execution if the system username is 'justin' (anti-analysis check). The package is a trojanized directory-tree generator that also bundles unrelated CSS-processing dependencies (postcss, cssnano, purgecss) as cover.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 01:30 PM
- analyzed
- Jul 12, 2026, 01:35 PM
Related advisories
- tinyparrot@0.4.1
- react-hot-svg@1.1.5
- notify-utilities@1.3.5
- client-cookies-agent@99.9.7
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- eth-react-redirection@1.0.0
- ohcm-culture-formatting@5.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.