LWA-2026-6715 MAL-2026-10451 ↗ confirmed malware

gifuct@2.1.2

Malicious code in gifuct (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

gifuct@2.1.2 typosquats the real gifuct-js GIF parser library. On require(), the package downloads a remote binary from filament-zap[.]vercel[.]app/service/assets/fetchBinary (Windows) or fetchLinuxBinary (Linux), writes it to ~/.local/share/WinMetrics/WinMetrics (Linux) or %LOCALAPPDATA%\Programs\WinMetrics\WinService.exe (Windows), and spawns it as a detached background process. The package wraps the real gifuct-js to appear functional while the downloader executes in the background.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 04:14 PM
analyzed
Jul 13, 2026, 04:15 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.