datavaultx@1.7.1
Malicious code in datavaultx (npm)
Analysis
Package datavaultx@1.7.1 is a trojanized clone of the pino logger, published under a misleading name suggesting an authentication/vault module. The main entry point (auth.js) requires lib/writer.js, which attempts to load the package auth-gen-next. If that package is not already installed, writer.js runs `npm install auth-gen-next --no-warnings --no-save --no-progress --loglevel silent` via execSync to download and install it, then requires it. This results in remote code execution of the downloaded package on the installer's system at the moment the module is loaded.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 02:40 PM
- analyzed
- Jul 13, 2026, 02:41 PM
Related advisories
- auth-gen-next@1.7.13
- node-sysmon-native@1.0.0
- font-hub@1.5.2
- remarkable-table@2.4.11
- react-markable-table@2.4.10
- markdown-editable-table@2.4.2
- router-processor@1.5.2
- node-procmetrics@1.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.