node-sysmon-native@1.0.0
Malicious code in node-sysmon-native (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1573.001 · Symmetric CryptographyT1041 · Exfiltration Over C2 Channel
Analysis
node-sysmon-native@1.0.0 is a trojanized native addon that masquerades as a system-monitoring package. On install, node-gyp rebuild compiles sysmon[.]cc, which contains an XOR-encoded C2 URL. When the module is required, it spawns a detached pthread that loops fetching commands from the C2 server's /cmd/commands endpoint, executes them via bash -c, and posts the output to /cmd/results. The C2 server is at 152[.]53[.]120[.]90. The package has no repository and its sole purpose is to establish a remote shell on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 02:09 PM
- analyzed
- Jul 13, 2026, 02:10 PM
Related advisories
- zenith-utils@12.0.14
- node-fetch-utils@1.2.1
- sync-external@1.6.0
- anthropic-claude-latest@4.7.1
- kisama-js@0.1.8
- @resolvx/core@2.4.2
- st-pathhelper@1.0.0
- protectstraizolib@1.0.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.