LWA-2026-6692 MAL-2026-10447 ↗ confirmed malware

remarkable-table@2.4.11

Malicious code in remarkable-table (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Package "remarkable-table" is a trojanized clone of the legitimate "markdown-table" library. The preinstall hook (package/scripts/preinstall) runs index.d.js, which decodes a base64-encoded payload that fetches a remote JavaScript payload from hxxps://everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=root3 and executes it via eval. This gives the attacker arbitrary code execution on any system that installs the package, enabling credential theft, backdoor installation, or further payload delivery.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 12:40 PM
analyzed
Jul 13, 2026, 12:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.