remarkable-table@2.4.11
Malicious code in remarkable-table (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Package "remarkable-table" is a trojanized clone of the legitimate "markdown-table" library. The preinstall hook (package/scripts/preinstall) runs index.d.js, which decodes a base64-encoded payload that fetches a remote JavaScript payload from hxxps://everydaynodechecker-39143n[.]vercel[.]app/api/key?mem=root3 and executes it via eval. This gives the attacker arbitrary code execution on any system that installs the package, enabling credential theft, backdoor installation, or further payload delivery.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 12:40 PM
- analyzed
- Jul 13, 2026, 12:41 PM
Related advisories
- react-markable-table@2.4.10
- markdown-editable-table@2.4.2
- router-processor@1.5.2
- node-procmetrics@1.0.6
- @fuji-web-components/maps@99.9.1
- awesome-terminal@1.0.3
- type-context@3.2.7
- terminal-mascot@3.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.