sync-grove@1.0.1
Malicious code in sync-grove (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel
Analysis
The postinstall hook in setup.js downloads an AES-encrypted payload from hxxp://player[.]sweetprovider[.]org/getKey[.]php and a decryption key from hxxp://player[.]sweetprovider[.]org/generateRandomKey[.]php, decrypts it, and executes the result via shelljs.exec(). This gives the remote server arbitrary code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 07:05 AM
- analyzed
- Jul 16, 2026, 07:06 AM
Related advisories
- chai-as-hardened@7.0.9
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
- chai-as-verified@7.1.5
- eth-react-redirection@1.0.0
- chain-js-utils@2.1.1
- chain-await-dom@1.3.4
- chai-as-structured@7.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.